Junglewise Threat Intelligence

CVE-2026-75432: yaml-cpp stack underflow in Scanner indent handling

CVE-2026-75432 · Severity: info · Published 2026-09-22

Executive brief

yaml-cpp is a YAML parser library used in applications that process YAML configuration files and data. A flaw in the Scanner component allows a remote attacker to cause a denial of service by triggering a crash through malformed YAML input that exploits improper stack management.

Technical details

The vulnerability is a stack underflow (CWE-822) in the Scanner::PopIndent() and Scanner::PushIndentTo() functions in src/scanner.cpp. When parsing specially crafted YAML, the indentation stack can be popped beyond its valid bounds, causing a dereference of an empty stack and a deterministic crash. This is triggered via network input when an application uses yaml-cpp to parse untrusted YAML data.

Affected products

  • yaml-cpp yaml-cpp 0.9.0

Timeline

  • 2026-09-22: disclosed
  • 2026-08-10: patched

References