PT-2025-31053 · Unknown+1 · Yarnpkg Yarn+1

Mmmsssttt

·

Published

2025-07-28

·

Updated

2025-07-31

·

CVE-2025-8262

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions yarnpkg Yarn versions up to 1.22.22
Description A vulnerability exists in the explodeHostedGitFragment function within the src/resolvers/exotics/hosted-git-resolver.js file. This manipulation results in inefficient regular expression complexity, potentially allowing for remote exploitation.
Recommendations Apply the patch identified as 97731871e674bf93bcbf29e9d3258da8685f3076 to resolve this issue.

Exploit

Fix

Resource Exhaustion

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-8262

Affected Products

Debian
Yarnpkg Yarn