Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 44 yarnpkg Update Vendor Bundle Advisory FEDORA-2026-db0c5d039c

fedora
Calendar Grey March 17, 2026
Dist Fedora Esm H88
Improve security and reliability on Fedora 44 with yarnpkg update vendor bundle for enhanced dependency management.
Update vendor bundle.

Summary

Fast, reliable, and secure dependency management.

Update Information:

Update vendor bundle.

Change Log

* Sat Mar 7 2026 Sandro Mani - 1.22.22-17 - Refresh vendor bundle

References


[ 1 ] Bug #2422491 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2422491 [ 2 ] Bug #2422506 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2422506

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-db0c5d039c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: yarnpkg
Product: Fedora 44
Version: 1.22.22
Release: 17.fc44
Summary: Fast, reliable, and secure dependency management.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here