YAML::Syck version 1.47 has been released to fix multiple memory-safety vulnerabilities in the Perl module’s bundled libsyck library, all reachable through the default Load or LoadFile parsing path when handling untrusted YAML. The disclosed issues include CVE-2026-57075, an out-of-bounds read in syck_base64dec caused by indexing a 256-entry lookup table with a signed char; CVE-2026-57076, a heap use-after-free in syck_hdlr_add_anchor when an anchor name is reused as an anchors-table key; and CVE-2026-57077, an out-of-bounds read in newline_len during block-scalar lexing at a document boundary. Advisories say affected versions are those before 1.47, and note that CVE-2026-57077 is an incomplete-fix follow-on to CVE-2025-11683.
Project maintainers also patched CVE-2026-13713, described in the code and release notes as a use-after-free/double-free involving anchor nodes that can cause a remote crash denial of service. The remediation adds targeted code fixes, changes anchor-table key ownership, introduces deferred cleanup for retired parser nodes, adds regression tests for each CVE, and expands AddressSanitizer-based CI to reproduce the vulnerable behavior and verify the fixes. The 1.47 release further hardens syck_base64dec() with bounds checks and sets a default Load maximum depth of 512 to reduce the risk of C-stack exhaustion from deeply nested YAML or JSON input.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-17, separate oss-sec advisories disclosed CVE-2026-57075, CVE-2026-57076, and CVE-2026-57077 affecting YAML::Syck versions before 1.47. The advisories described an out-of-bounds read in syck_base64dec, a heap use-after-free in anchor handling, and an out-of-bounds read in newline_len, and recommended upgrading to 1.47 or later.
On 2026-07-13, YAML::Syck version 1.47 was released to fix four memory-safety flaws in bundled libsyck code: CVE-2026-57075, CVE-2026-57076, CVE-2026-57077, and CVE-2026-13713. The release also added hardening and regression coverage, including AddressSanitizer-based CI checks and a default Load max depth of 512.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourcemetacpan.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.