VYPR

rpm package

almalinux/perl-YAML-Syck

pkg:rpm/almalinux/perl-YAML-Syck

Vulnerabilities (2)

  • CVE-2026-13713MedJul 16, 2026
    affected < 1.30-7.el8_10fixed 1.30-7.el8_10

    YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node sto

  • CVE-2026-4177CriMar 16, 2026
    affected < 1.30-6.el8_10fixed 1.30-6.el8_10

    YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the