Package
langfuse-fips-3-worker
Component
js-yaml
Latest update
Fixed version
3.205.1-r2
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
3.205.1-r2Status
Impact
The remaining detection is a transitive js-yaml 3.14.x copy required by a dependency pinned to the 3.x API. CVE-2026-53550 has no fix in the 3.x release line (the patch exists only in js-yaml 4.2.0), and js-yaml 4.x is a breaking API change the 3.x consumer cannot adopt, so no compatible fix is currently available.
Status