Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nodeca

First CVE: Jun 28, 2013Active for: 13 yearsTotal CVEs: 6

Nodeca maintains a narrowly scoped JavaScript library ecosystem centered on the widely embedded js-yaml parser, where the durable signal clusters around input-validation weaknesses and prototype-pollution issues characteristic of JavaScript deserialization and object-manipulation code. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nodeca over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 28, 2013
13 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-4660MEDIUM
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a cr
Jun 28, 20136.843NOYES
CVE-2026-59869HIGH
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only
Jul 8, 20267.535NONO
CVE-2026-59868HIGH
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only
Jul 8, 20267.533NONO
CVE-2026-59870HIGH
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses omapTag.addItem() to perform a li
Jul 8, 20267.530NONO
CVE-2026-53550MEDIUM
js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by re
Jun 22, 20265.327NONO
CVE-2025-64718MEDIUM
js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document vi
Nov 13, 20255.322NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (83.3%)
Unknown1 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High0 (0.0%)
Unknown1 (16.7%)
User Interaction
None5 (83.3%)
Unknown1 (16.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (83.3%)
Unknown1 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
16.7% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nodeca.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nodeca — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nodeca's Products

View all 2 CNAs →

Top CWEs