{"id":"CVE-2025-9308","summary":"yarnpkg Yarn request-manager.js setOptions redos","details":"A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.","modified":"2026-08-12T03:51:43.789374341Z","published":"2025-08-21T16:02:12.172Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"1.22.6"},{"last_affected":"1.22.6"},{"introduced":"1.22.7"},{"last_affected":"1.22.7"},{"introduced":"1.22.8"},{"last_affected":"1.22.8"},{"introduced":"1.22.9"},{"last_affected":"1.22.9"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB","cwe_ids":["CWE-1333","CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9308.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9308.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9308"},{"type":"ADVISORY","url":"https://vuldb.com/?id.320913"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.633486"},{"type":"REPORT","url":"https://github.com/yarnpkg/yarn/pull/9203"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.320913"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yarnpkg/yarn","events":[{"introduced":"eee67d02ed09172d5360df0fa0b9c73e23449818"},{"last_affected":"740c38c3a962c30ddb344a919bbfb7065620714b"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.22.0"},{"last_affected":"1.22.0"},{"introduced":"1.22.1"},{"last_affected":"1.22.1"},{"introduced":"1.22.2"},{"last_affected":"1.22.2"},{"introduced":"1.22.3"},{"last_affected":"1.22.3"},{"introduced":"1.22.4"},{"last_affected":"1.22.4"},{"introduced":"1.22.5"},{"last_affected":"1.22.5"},{"introduced":"1.22.10"},{"last_affected":"1.22.10"},{"introduced":"1.22.11"},{"last_affected":"1.22.11"},{"introduced":"1.22.12"},{"last_affected":"1.22.12"},{"introduced":"1.22.13"},{"last_affected":"1.22.13"},{"introduced":"1.22.14"},{"last_affected":"1.22.14"},{"introduced":"1.22.15"},{"last_affected":"1.22.15"},{"introduced":"1.22.16"},{"last_affected":"1.22.16"},{"introduced":"1.22.17"},{"last_affected":"1.22.17"},{"introduced":"1.22.18"},{"last_affected":"1.22.18"},{"introduced":"1.22.19"},{"last_affected":"1.22.19"},{"introduced":"1.22.20"},{"last_affected":"1.22.20"},{"introduced":"1.22.21"},{"last_affected":"1.22.21"},{"introduced":"1.22.22"},{"last_affected":"1.22.22"},{"introduced":"0"}]}}],"versions":["1.22.0","1.22.1","1.22.10","1.22.11","1.22.12","1.22.13","1.22.14","1.22.15","1.22.16","1.22.17","1.22.18","1.22.19","1.22.2","1.22.20","1.22.21","1.22.22","1.22.3","1.22.4","1.22.5","v1.22.22","v1.22.21","v1.22.20","v1.22.19","v1.22.18","v1.22.17","v1.22.16","v1.22.15","v1.22.14","v1.22.13","v1.22.12","v1.22.11","v1.22.10","v1.22.5","v1.22.4","v1.22.3","v1.22.2","v1.22.1","v1.22.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9308.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"}]}