VDB
GCVE-110-MAGEIA-2025-194
GCVE-110-MAGEIA-2025-194
Advisory Published
CVE-2024-37890 yarnpkg: denial of service when handling a request with
many HTTP headers.
CVE-2024-48949 yarnpkg: Missing Validation in Elliptic's EDDSA Signature
Verification.
CVE-2024-12905 yarnpkg: link following and path traversal via
maliciously crafted tar file
And other vulnerabilities in the yarn's bundled nodejs components are
fixed too, see the references.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | yarnpkg | 0 (affected), 1.22.22-0.10.9.2.1.mga9 (unaffected) | — |
Browse GCVE Records
74,108 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.