{"id":"CVE-2025-11683","summary":"YAML::Syck versions before 1.36 for Perl has missing Null-Terminators which causes Out-of-Bounds Read and potential Information Disclosure","details":"YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure\n\nMissing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read\n\nThe issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.","modified":"2026-08-12T03:51:12.396456920Z","published":"2025-10-16T00:14:41.769Z","related":["openSUSE-SU-2026:10746-1","openSUSE-SU-2026:20771-1","openSUSE-SU-2026:21497-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11683.json","cna_assigner":"CPANSec","cwe_ids":["CWE-119"]},"references":[{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11683.json"},{"type":"ADVISORY","url":"https://metacpan.org/dist/YAML-Syck/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11683"},{"type":"FIX","url":"https://github.com/cpan-authors/YAML-Syck/pull/65"},{"type":"PACKAGE","url":"https://github.com/cpan-authors/YAML-Syck"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cpan-authors/yaml-syck","events":[{"introduced":"0"},{"fixed":"5240a54e6afb0bdabbaf11714475dd9b3d8f16fa"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:toddr:yaml\\:\\:syck:*:*:*:*:*:perl:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.36"}]}}],"versions":["1.35","1.34","1.33","1.32","1.31","1.30","1.30_01","1.29_01","1.28","1.28_01","1.27","1.26","1.24_02","1.24_01","1.23","1.22","1.21_01","1.20","1.15","1.14","1.13","1.12","1.11","1.10_07","1.10_06","1.10_05","1.10_04","1.10_03","1.10_02","1.10_01","1.10","1.09","1.08_01","1.08","1.07_01","1.07","1.05","1.04","1.03","1.02","1.01","1.00","0.99","0.98","0.97","0.96","0.95","0.94","0.91","0.90","0.88","0.87","0.86","0.85","0.84","0.82","0.81","0.80","0.72","0.71","0.70","0.67","0.66","0.65","0.64","0.63","0.62","0.61","0.60","0.46_01","0.45","0.44","0.43","0.42","0.41","0.40","0.38","0.37","0.36","0.35","0.34","0.33","0.32","0.31","0.30","0.29","0.28","0.27","0.26","0.25","0.24","0.23","0.22","0.21","0.20","0.19","0.18","0.17","0.16","0.15","0.14","0.13","0.12","0.11","0.10","0.09","0.08","0.07","0.06","0.05","0.04","0.03","0.02","0.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-11683.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}