Not that it's not important, but I assume this story's placement on the front page is a consequence of people thinking this impacts Yubikeys themselves through U2F (the way most people use keys) or SSH/PGP (the way most of the rest of people do).
Here's the commit that fixes the bug:
https://github.com/Yubico/yubikey-val/pull/59/commits/d0e4db...
It's... not great; it looks like they were accepting SQL metacharacters in hand-rolled non-parameterized SQL queries.
If you were running this project: (1) you should fix right away and presumably disregard the summary at the top of the advisory that this vulnerability would just allow DoS, and (2) once you do, tell the rest of us why you were running this thing; I'm sure we'd be interested in hearing your use case.