Back Linuxsecurity Fedora 43 yarnpkg Advisory 2026-a75abb3f2b CVE-2025
Fast, reliable, and secure dependency management. Update Information : Regenerate vendor tarball. Fixes CVE-2025-13465.
Fast, reliable, and secure dependency management.
Regenerate vendor tarball. Fixes CVE-2025-13465.
* Tue Jan 27 2026 Sandro Mani - 1.22.22-16 - Refresh bundle, fixes CVE-2025-13465 * Sat Jan 17 2026 Fedora Release Engineering - 1.22.22-15 - Rebuilt for
* Tue Jan 27 2026 Sandro Mani - 1.22.22-16 - Refresh bundle, fixes CVE-2025-13465 * Sat Jan 17 2026 Fedora Release Engineering - 1.22.22-15 - Rebuilt for
[ 1 ] Bug #2432997 - CVE-2025-13465 yarnpkg: prototype pollution in _.unset and _.omit functions [fedora-42] [ 2 ] Bug #2433048 - CVE-2025-13465 yarnpkg: prototype pollution in _.unset and _.omit functions [fedora-43]
[ 1 ] Bug #2432997 - CVE-2025-13465 yarnpkg: prototype pollution in _.unset and _.omit functions [fedora-42] [ 2 ] Bug #2433048 - CVE-2025-13465 yarnpkg: prototype pollution in _.unset and _.omit functions [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a75abb3f2b' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a75abb3f2b' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
