CVE Database
/

CVE-2025-11683

Back to search

CVE-2025-11683

Published: Oct 16, 2025

Modified: Oct 16, 2025

PUBLISHED

Description

YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.

VendorProductVersions

TODDR

YAML::Syck

affected
0 - < 1.36

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now