{"id":"CVE-2025-8262","summary":"yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos","details":"A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The patch is identified as 97731871e674bf93bcbf29e9d3258da8685f3076. It is recommended to apply a patch to fix this issue.","modified":"2026-08-12T03:51:35.651176253Z","published":"2025-07-28T07:02:05.616Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8262.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.22.6"},{"last_affected":"1.22.6"},{"introduced":"1.22.7"},{"last_affected":"1.22.7"},{"introduced":"1.22.8"},{"last_affected":"1.22.8"},{"introduced":"1.22.9"},{"last_affected":"1.22.9"}]}],"cna_assigner":"VulDB","cwe_ids":["CWE-1333","CWE-400"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8262.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8262"},{"type":"ADVISORY","url":"https://vuldb.com/?id.317850"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.617393"},{"type":"REPORT","url":"https://github.com/yarnpkg/yarn/pull/9199"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.317850"},{"type":"FIX","url":"https://github.com/yarnpkg/yarn/pull/9199/commits/97731871e674bf93bcbf29e9d3258da8685f3076"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yarnpkg/yarn","events":[{"introduced":"eee67d02ed09172d5360df0fa0b9c73e23449818"},{"last_affected":"740c38c3a962c30ddb344a919bbfb7065620714b"}],"database_specific":{"cpe":"cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.22.0"},{"last_affected":"1.22.0"},{"introduced":"1.22.1"},{"last_affected":"1.22.1"},{"introduced":"1.22.2"},{"last_affected":"1.22.2"},{"introduced":"1.22.3"},{"last_affected":"1.22.3"},{"introduced":"1.22.4"},{"last_affected":"1.22.4"},{"introduced":"1.22.5"},{"last_affected":"1.22.5"},{"introduced":"1.22.10"},{"last_affected":"1.22.10"},{"introduced":"1.22.11"},{"last_affected":"1.22.11"},{"introduced":"1.22.12"},{"last_affected":"1.22.12"},{"introduced":"1.22.13"},{"last_affected":"1.22.13"},{"introduced":"1.22.14"},{"last_affected":"1.22.14"},{"introduced":"1.22.15"},{"last_affected":"1.22.15"},{"introduced":"1.22.16"},{"last_affected":"1.22.16"},{"introduced":"1.22.17"},{"last_affected":"1.22.17"},{"introduced":"1.22.18"},{"last_affected":"1.22.18"},{"introduced":"1.22.19"},{"last_affected":"1.22.19"},{"introduced":"1.22.20"},{"last_affected":"1.22.20"},{"introduced":"1.22.21"},{"last_affected":"1.22.21"},{"introduced":"1.22.22"},{"last_affected":"1.22.22"},{"introduced":"0"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["1.22.0","1.22.1","1.22.10","1.22.11","1.22.12","1.22.13","1.22.14","1.22.15","1.22.16","1.22.17","1.22.18","1.22.19","1.22.2","1.22.20","1.22.21","1.22.22","1.22.3","1.22.4","1.22.5","v1.22.22","v1.22.21","v1.22.20","v1.22.19","v1.22.18","v1.22.17","v1.22.16","v1.22.15","v1.22.14","v1.22.13","v1.22.12","v1.22.11","v1.22.10","v1.22.5","v1.22.4","v1.22.3","v1.22.2","v1.22.1","v1.22.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8262.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"}]}