CVE-2026-57077
HIGHYAML::Syck < 1.47 - newline_len Out-of-Bounds Read
Title source: manualDescription
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover. Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.
References (3)
Core 3
Core References
Patch patch
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b.patch
Release Notes release-notes
https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes
Related related
https://www.cve.org/CVERecord?id=CVE-2025-11683
Scores
CVSS v3
7.7
EPSS
0.0014
EPSS Percentile
3.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-125
Status
published
Products (1)
TODDR/YAML::Syck
< 1.47
Published
Jul 16, 2026
Tracked Since
Jul 17, 2026