Description
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
INFO
Published Date :
2026-03-16T22:30:25.367Z
Last Modified :
2026-03-17T14:04:53.600Z
Source :
CPANSec
AFFECTED PRODUCTS
The following products are affected by CVE-2026-4177 vulnerability.
| Vendors | Products |
|---|---|
| Toddr |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-4177.