CVE-2025-9308

Name
CVE-2025-9308
Description
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/yarnpkg/yarn/pull/9203
signature https://vuldb.com/?ctiid.320913
vdb-entry https://vuldb.com/?id.320913
third-party-advisory https://vuldb.com/?submit.633486

Match rules

CPE URI Source package Min version Max version
yarn == 1.22.0 == 1.22.0
yarn == 1.22.1 == 1.22.1
yarn == 1.22.2 == 1.22.2
yarn == 1.22.3 == 1.22.3
yarn == 1.22.4 == 1.22.4
yarn == 1.22.5 == 1.22.5
yarn == 1.22.6 == 1.22.6
yarn == 1.22.7 == 1.22.7
yarn == 1.22.8 == 1.22.8
yarn == 1.22.9 == 1.22.9
yarn == 1.22.10 == 1.22.10
yarn == 1.22.11 == 1.22.11
yarn == 1.22.12 == 1.22.12
yarn == 1.22.13 == 1.22.13
yarn == 1.22.14 == 1.22.14
yarn == 1.22.15 == 1.22.15
yarn == 1.22.16 == 1.22.16
yarn == 1.22.17 == 1.22.17
yarn == 1.22.18 == 1.22.18
yarn == 1.22.19 == 1.22.19
yarn == 1.22.20 == 1.22.20
yarn == 1.22.21 == 1.22.21
yarn == 1.22.22 == 1.22.22
cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:* yarn >= None <= 1.22.22

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
yarn edge-community 1.22.22-r1 Ed Robinson <ed@reevoo.com> possibly vulnerable
yarn 3.22-community 1.22.22-r1 Ed Robinson <ed@reevoo.com> possibly vulnerable