rpm package
almalinux/perl-YAML-Syck
pkg:rpm/almalinux/perl-YAML-Syck
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-13713 | Med | 6.2 | < 1.30-7.el8_10 | 1.30-7.el8_10 | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node sto | |
| CVE-2026-4177 | Cri | 9.1 | < 1.30-6.el8_10 | 1.30-6.el8_10 | Mar 16, 2026 | YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the |
- affected < 1.30-7.el8_10fixed 1.30-7.el8_10
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node sto
- affected < 1.30-6.el8_10fixed 1.30-6.el8_10
YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the