The heap overflow occurs when class names exceed the initial 512-byte allocation.
The base64 decoder could read past the buffer end on trailing newlines.
strtok mutated n->type_id in place, corrupting shared node data.
A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 1.37 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4525-1 | libyaml-syck-perl security update |
Debian DSA |
DSA-6175-1 | libyaml-syck-perl security update |
Mon, 23 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toddr yaml\
|
|
| CPEs | cpe:2.3:a:toddr:yaml\:\:syck:*:*:*:*:*:perl:*:* | |
| Vendors & Products |
Toddr yaml\
|
Tue, 17 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Tue, 17 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toddr
Toddr yaml::syck |
|
| Vendors & Products |
Toddr
Toddr yaml::syck |
Tue, 17 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 16 Mar 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return. | |
| Title | YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter | |
| Weaknesses | CWE-122 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-03-17T14:04:53.600Z
Reserved: 2026-03-14T19:36:56.710Z
Link: CVE-2026-4177
Updated: 2026-03-17T01:34:04.213Z
Status : Analyzed
Published: 2026-03-16T23:16:21.543
Modified: 2026-03-23T18:17:31.370
Link: CVE-2026-4177
OpenCVE Enrichment
Updated: 2026-03-24T10:49:44Z
Debian DLA
Debian DSA