{"id":"CVE-2026-57075","summary":"YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec","details":"YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.\n\nThe base64 decoder in the bundled libsyck indexes the 256-entry static table b64_xtable with a signed char, so any !!binary byte \u003e= 0x80 sign-extends to a negative index and reads before the table. The decoder receives the raw bytes of any !!binary node, a standard YAML type not gated by $LoadBlessed or $LoadCode, so it is reached on the default Load path.\n\nAny caller that runs Load or LoadFile on an untrusted document containing a !!binary scalar with a high-bit byte triggers the read, and the value read can surface in the decoded result.","modified":"2026-07-19T03:31:08.487645369Z","published":"2026-07-16T21:39:22.991Z","related":["openSUSE-SU-2026:11299-1"],"database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57075.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/17/2"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57075.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57075"},{"type":"FIX","url":"https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b.patch"},{"type":"PACKAGE","url":"https://github.com/toddr/YAML-Syck"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cpan-authors/YAML-Syck","events":[{"introduced":"0"},{"fixed":"44c90a109ec3215ee7ce747bd11209835e123d8b"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.47"}]}}],"versions":["1.46","1.45","1.44","1.43","1.42","1.41","1.39","1.38","1.37","1.37_01","v1.36","1.36","v1.35","1.35","v1.34","1.34","v1.33","1.33","v1.32","1.32","v1.31","1.31","v1.30","1.30","v1.30_01","1.30_01","v1.29_01","1.29_01","v1.28","1.28","v1.28_01","1.28_01","1.27","1.26","1.24_02","1.24_01","1.23","1.22","1.21_01","1.20","1.15","1.14","1.13","1.12","1.11","1.10_07","1.10_06","1.10_05","1.10_04","1.10_03","1.10_02","1.10_01","1.10","1.09","1.08_01","1.08","1.07_01","1.07","1.05","1.04","1.03","1.02","1.01","1.00","0.99","0.98","0.97","0.96","0.95","0.94","0.91","0.90","0.88","0.87","0.86","0.85","0.84","0.82","0.81","0.80","0.72","0.71","0.70","0.67","0.66","0.65","0.64","0.63","0.62","0.61","0.60","0.46_01","0.45","0.44","0.43","0.42","0.41","0.40","0.38","0.37","0.36","0.35","0.34","0.33","0.32","0.31","0.30","0.29","0.28","0.27","0.26","0.25","0.24","0.23","0.22","0.21","0.20","0.19","0.18","0.17","0.16","0.15","0.14","0.13","0.12","0.11","0.10","0.09","0.08","0.07","0.06","0.05","0.04","0.03","0.02","0.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57075.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}