Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Fedora 43 yarnpkg Important Code Exec Fix CVE-2026-4800 2026-085abeea02

fedora
Calendar Grey April 12, 2026
Dist Fedora Esm H88
Tackling CVE-2026-4800 in Fedora 43 by using yarnpkg update for improved security and protection against vulnerabilities
Refresh vendor bundle, fixes CVE-2026-4800

Summary

Fast, reliable, and secure dependency management.

Update Information:

Refresh vendor bundle, fixes CVE-2026-4800. Update vendor bundle.

Change Log

* Thu Apr 2 2026 Sandro Mani - 1.22.22-18 - Add yarn-jsyaml4.patch - Refresh vendor bundle, fixes CVE-2026-4800 * Sat Mar 7 2026 Sandro Mani - 1.22.22-17 - Refresh vendor bundle

References


[ 1 ] Bug #2422491 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2422491 [ 2 ] Bug #2422506 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2422506 [ 3 ] Bug #2454058 - CVE-2026-4800 yarnpkg: lodash: Arbitrary code execution via untrusted input in template imports [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454058

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-085abeea02' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: yarnpkg
Product: Fedora 43
Version: 1.22.22
Release: 18.fc43
Summary: Fast, reliable, and secure dependency management.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here