Junglewise Threat Intelligence

CVE-2026-4177: YAML::Syck heap buffer overflow and multiple vulnerabilities

CVE-2026-4177 · Severity: critical · CVSS 9.1 · Published 2026-03-16

Executive brief

YAML::Syck is a popular Perl library used for processing YAML and JSON data formats. Multiple security vulnerabilities have been identified that could allow an attacker to crash applications using this library or potentially gain unauthorized access to data. These issues occur when the library handles specially crafted data, such as very long class names or specific encoded strings.

Technical details

YAML::Syck through version 1.36 contains four distinct C-layer vulnerabilities. 1) A heap buffer overflow in the YAML emitter occurs when class names exceed a fixed 512-byte allocation during tag generation. 2) A buffer over-read exists in the base64 decoder due to missing bounds checks when encountering trailing newlines. 3) Data corruption occurs in the parser because 'strtok' was used to mutate shared node data in place. 4) A memory leak exists in 'syck_hdlr_add_anchor' when processing duplicate anchors. These issues are addressed in version 1.37_01 by implementing dynamic buffer growth, improved bounds checking, and proper memory management.

Affected products

  • TODDR YAML::Syck through 1.36

Timeline

  • 2026-03-16: disclosed
  • 2026-03-16: advisory
  • 2026-03-14: patched: Fixes committed to GitHub repository

References