A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.
References
Configurations
No configuration.
History
21 Aug 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/yarnpkg/yarn/pull/9203 - |
21 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-21 16:15
Updated : 2025-08-21 18:15
NVD link : CVE-2025-9308
Mitre link : CVE-2025-9308
CVE.ORG link : CVE-2025-9308
JSON object : View
Products Affected
No product.