Metrics
Affected Vendors & Products
Fri, 12 Sep 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:* |
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yarnpkg
Yarnpkg yarn |
|
| Vendors & Products |
Yarnpkg
Yarnpkg yarn |
Fri, 22 Aug 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | yarnpkg Yarn request-manager.js setOptions redos | |
| Weaknesses | CWE-1333 CWE-400 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-21T16:02:12.172Z
Updated: 2025-08-21T17:32:14.661Z
Reserved: 2025-08-21T05:58:24.411Z
Link: CVE-2025-9308
Updated: 2025-08-21T17:24:43.236Z
Status : Analyzed
Published: 2025-08-21T16:15:35.790
Modified: 2025-09-12T12:58:04.847
Link: CVE-2025-9308
ReportizFlow