YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.
The base64 decoder in the bundled libsyck indexes the 256-entry static table b64_xtable with a signed char, so any !!binary byte >= 0x80 sign-extends to a negative index and reads before the table. The decoder receives the raw bytes of any !!binary node, a standard YAML type not gated by $LoadBlessed or $LoadCode, so it is reached on the default Load path.
Any caller that runs Load or LoadFile on an untrusted document containing a !!binary scalar with a high-bit byte triggers the read, and the value read can surface in the decoded result.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-yaml-syck | Aug 24, 2026 | Jul 16, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-YAML-SyckUpgrade perl-YAML-Syck-debuginfo | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-YAML-Syck-debugsourceUpgrade perl-YAML-SyckUpgrade perl-YAML-Syck-testsUpgrade perl-YAML-Syck-debuginfo | Aug 10, 2026 | Jul 16, 2026 |
| Debian | — | Upgrade libyaml-syck-perl | Aug 11, 2026 | Aug 11, 2026 |
| Freebsd | — | Upgrade p5-YAML-Syck | Sep 28, 2026 | Sep 26, 2026 |
| Redhat_linux | — | No solution exists | Jul 20, 2026 | Jul 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub