YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.
In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover.
Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.
CVSS Details
- CVSS 3.1 Base Score: 7.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade perl-yaml-syck | Aug 24, 2026 | Jul 16, 2026 |
| Amazon Linux Ami 2 | — | Upgrade perl-YAML-SyckUpgrade perl-YAML-Syck-debuginfo | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-YAML-Syck-debugsourceUpgrade perl-YAML-Syck-debuginfoUpgrade perl-YAML-SyckUpgrade perl-YAML-Syck-tests | Aug 10, 2026 | Jul 16, 2026 |
| Debian | — | Upgrade libyaml-syck-perl | Aug 11, 2026 | Aug 11, 2026 |
| Freebsd | — | Upgrade p5-YAML-Syck | Sep 28, 2026 | Sep 26, 2026 |
| Redhat_linux | — | No solution exists | Jul 20, 2026 | Jul 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub