Back Linuxsecurity Fedora 44 yarnpkg Update Vendor Bundle Advisory FEDORA-2026
Fast, reliable, and secure dependency management. Update Information : Update vendor bundle.
Fast, reliable, and secure dependency management.
Update vendor bundle.
* Sat Mar 7 2026 Sandro Mani - 1.22.22-17 - Refresh vendor bundle
* Sat Mar 7 2026 Sandro Mani - 1.22.22-17 - Refresh vendor bundle
[ 1 ] Bug #2422491 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-42] [ 2 ] Bug #2422506 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-43]
[ 1 ] Bug #2422491 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-42] [ 2 ] Bug #2422506 - CVE-2025-64718 yarnpkg: js-yaml prototype pollution in merge [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-db0c5d039c' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-db0c5d039c' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
