YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure
Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read
The issue is seen with complex YAML files with a hash of all keys and empty values. There is no indication that the issue leads to accessing memory outside that allocated to the module.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade perl-YAML-Syck-debuginfoUpgrade perl-YAML-Syck | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade perl-YAML-SyckUpgrade perl-YAML-Syck-debuginfoUpgrade perl-YAML-Syck-debugsource | Oct 28, 2025 | Oct 16, 2025 |
| Debian | — | Upgrade libyaml-syck-perl | Jan 12, 2026 | Jan 12, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 16, 2025 |
| Ubuntu | — | Upgrade libyaml-syck-perlUpgrade libyaml-syck-perl (Ubuntu Pro) | Oct 30, 2025 | Oct 28, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub