CVE-2025-8262 is a problematic vulnerability affecting yarnpkg Yarn up to version 1.22.22, specifically within the explodeHostedGitFragment function in src/resolvers/exotics/hosted-git-resolver.js. This flaw involves inefficient regular expression complexity, allowing a remote attacker to potentially cause a denial of service (DoS) by exploiting this weakness. The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating a high severity. It can be exploited remotely with low attack complexity and no user interaction required, leading to high availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.22.22CPE matchmatch criteria | cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.