yarnpkg Yarn request-manager.js setOptions redos
Published Aug 21, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.21%
Description
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
-
- Version 1.22.0StatusaffectedConstraints-
- Version 1.22.1StatusaffectedConstraints-
- Version 1.22.10StatusaffectedConstraints-
- Version 1.22.11StatusaffectedConstraints-
- Version 1.22.12StatusaffectedConstraints-
- Version 1.22.13StatusaffectedConstraints-
- Version 1.22.14StatusaffectedConstraints-
- Version 1.22.15StatusaffectedConstraints-
- Version 1.22.16StatusaffectedConstraints-
- Version 1.22.17StatusaffectedConstraints-
- Version 1.22.18StatusaffectedConstraints-
- Version 1.22.19StatusaffectedConstraints-
- Version 1.22.2StatusaffectedConstraints-
- Version 1.22.20StatusaffectedConstraints-
- Version 1.22.21StatusaffectedConstraints-
- Version 1.22.22StatusaffectedConstraints-
- Version 1.22.3StatusaffectedConstraints-
- Version 1.22.4StatusaffectedConstraints-
- Version 1.22.5StatusaffectedConstraints-
- Version 1.22.6StatusaffectedConstraints-
- Version 1.22.7StatusaffectedConstraints-
- Version 1.22.8StatusaffectedConstraints-
- Version 1.22.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Yarnpkg | Yarn | n/a |
|
No data.
Migration Toolkit for Virtualization
migration-toolkit-virtualization/mtv-console-plugin-rhel9
Fix deferred
Migration Toolkit for Virtualization
mtv-candidate/mtv-console-plugin-rhel9
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/kiali-ossmc-rhel8
Fix deferred
OpenShift Service Mesh 2
openshift-service-mesh/kiali-rhel8
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/kiali-operator-bundle
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/kiali-ossmc-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9
Fix deferred
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9-operator
Fix deferred
Red Hat Enterprise Linux 8
grafana
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-agent-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-extensions-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel9
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/console-plugin-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/dex-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/gitops-operator-bundle
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/gitops-rhel8
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/gitops-rhel8-operator
Fix deferred
Red Hat OpenShift GitOps
openshift-gitops-1/must-gather-rhel8
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | Fix deferred | n/a |
| Migration Toolkit for Virtualization | mtv-candidate/mtv-console-plugin-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-ossmc-rhel8 | Fix deferred | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-operator-bundle | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-ossmc-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9 | Fix deferred | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9-operator | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | grafana | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-agent-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-extensions-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/console-plugin-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/dex-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-operator-bundle | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel8-operator | Fix deferred | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/must-gather-rhel8 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-9308 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2390129 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25475 Advisory
- https://github.com/yarnpkg/yarn/pull/9203 exploitissue-trackingIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-9308
- https://vuldb.com/?ctiid.320913 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.320913 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.633486 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2025-9308
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-9308 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2390129 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25475 | Advisory | |
| https://github.com/yarnpkg/yarn/pull/9203 | exploitissue-trackingIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-9308 | ||
| https://vuldb.com/?ctiid.320913 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.320913 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.633486 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2025-9308 |
Change history (0)
No recorded changes yet.