{"id":"CVE-2026-57076","summary":"YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor","details":"YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor.\n\nIn the bundled libsyck an anchor name allocated by syck_strndup is stored both as node-\u003eanchor, freed when the node is freed, and as the key in the parser's anchors table. Freeing the node frees the shared key, and a later anchor redefinition makes st_delete compare against the freed key, so st_strcmp reads freed heap memory. Anchors are a standard YAML feature and need no special flags, so this is reached on the default Load path.\n\nAny caller that runs Load or LoadFile on an untrusted document that redefines an anchor reaches the read of freed memory.","modified":"2026-07-22T04:28:37.080596Z","published":"2026-07-16T21:40:59.686Z","related":["openSUSE-SU-2026:11299-1"],"database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57076.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/17/3"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57076.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57076"},{"type":"FIX","url":"https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b.patch"},{"type":"PACKAGE","url":"https://github.com/toddr/YAML-Syck"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cpan-authors/YAML-Syck","events":[{"introduced":"0"},{"fixed":"44c90a109ec3215ee7ce747bd11209835e123d8b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.47"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.46","1.45","1.44","1.43","1.42","1.41","1.39","1.38","1.37","1.37_01","v1.36","1.36","v1.35","1.35","v1.34","1.34","v1.33","1.33","v1.32","1.32","v1.31","1.31","v1.30","1.30","v1.30_01","1.30_01","v1.29_01","1.29_01","v1.28","1.28","v1.28_01","1.28_01","1.27","1.26","1.24_02","1.24_01","1.23","1.22","1.21_01","1.20","1.15","1.14","1.13","1.12","1.11","1.10_07","1.10_06","1.10_05","1.10_04","1.10_03","1.10_02","1.10_01","1.10","1.09","1.08_01","1.08","1.07_01","1.07","1.05","1.04","1.03","1.02","1.01","1.00","0.99","0.98","0.97","0.96","0.95","0.94","0.91","0.90","0.88","0.87","0.86","0.85","0.84","0.82","0.81","0.80","0.72","0.71","0.70","0.67","0.66","0.65","0.64","0.63","0.62","0.61","0.60","0.46_01","0.45","0.44","0.43","0.42","0.41","0.40","0.38","0.37","0.36","0.35","0.34","0.33","0.32","0.31","0.30","0.29","0.28","0.27","0.26","0.25","0.24","0.23","0.22","0.21","0.20","0.19","0.18","0.17","0.16","0.15","0.14","0.13","0.12","0.11","0.10","0.09","0.08","0.07","0.06","0.05","0.04","0.03","0.02","0.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57076.json","vanir_signatures_modified":"2026-07-22T04:28:37Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"205949390577844048625194730347820491351","length":354},"id":"CVE-2026-57076-07d6750d","signature_type":"Function","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"syck_.c","function":"syck_st_free"}},{"source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"function":"syck_base64dec","file":"emitter.c"},"deprecated":false,"digest":{"function_hash":"326582959051301847547394615690452582809","length":1228},"id":"CVE-2026-57076-11b54e13","signature_type":"Function","signature_version":"v1"},{"digest":{"line_hashes":["153659563404254961675387871074310784069","238603781768247395376034017371589287208","194492483442587170580378982103270455711","18951947394846091036918930740782989621","54883433251445638069494168451322010540","56770392230353912212937218086181654062","175204374287167279126339530782513813824"],"threshold":0.9},"id":"CVE-2026-57076-41da57bc","signature_type":"Line","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"emitter.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["294383180027775892745666706312534019452","130998452209541435186565716819320512344","236647752601270572743049009509140267253","119152905233745251099553992089053274191","189396070798767280761059661544608526192","176734052533153087529477162418257736087","251876608254463756416520223451141109766","73111910942660763149654038567500359561","198909418965871326355592002471057239688","66748749295714258781636004316398720563","119152905233745251099553992089053274191","189396070798767280761059661544608526192","176734052533153087529477162418257736087","12107093945058425387014483290229305476","87048951880703195251423495550003510856","29816656809461522764555329716499096230","82010664234264932568129467259937814213","271089262542772998061079533021026026107","10501327679000650957840829582799107777","38465091907257408374363037593680334734","183455587666296399578388097670965746541"],"threshold":0.9},"id":"CVE-2026-57076-6db7c1df","signature_type":"Line","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"handler.c"}},{"target":{"file":"syck_.c"},"deprecated":false,"digest":{"line_hashes":["300739074869227694518400055323772669415","297565083208233808283691651223099082827","26407522250850449308517377679101468492","261085206708920514973862133584494079795","130026790572182239191042056231752694159","263718777400305828631063872972097778935","10942217524268166655663490020323927553","163496723598585183444973455442679174080","308185686592451130514126114284990629249","150711256225834430413627958930645429452","229384713873150713362683108144110899935","213072484150950808188445861800262235123","42071503780153570395348125200549668486"],"threshold":0.9},"id":"CVE-2026-57076-7062aca5","signature_type":"Line","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b"},{"signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"token.c","function":"sycklex_yaml_utf8"},"deprecated":false,"digest":{"function_hash":"162989237942083865717985892003361415813","length":38190},"id":"CVE-2026-57076-7ddaac19","signature_type":"Function"},{"id":"CVE-2026-57076-8c46914c","signature_type":"Function","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"handler.c","function":"syck_hdlr_remove_anchor"},"deprecated":false,"digest":{"function_hash":"192005287857108775521087267063681919651","length":354}},{"signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"syck_.c","function":"syck_new_parser"},"deprecated":false,"digest":{"function_hash":"2513376158406347726063971426490200103","length":549},"id":"CVE-2026-57076-9c2962d7","signature_type":"Function"},{"target":{"file":"syck_.c","function":"syck_st_free_nodes"},"deprecated":false,"digest":{"function_hash":"275898697991629277122893737114381470555","length":164},"id":"CVE-2026-57076-a7deafd4","signature_type":"Function","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b"},{"deprecated":false,"digest":{"function_hash":"168447789732427871208928294987378522824","length":142},"id":"CVE-2026-57076-c18ffd5d","signature_type":"Function","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"token.c","function":"newline_len"}},{"deprecated":false,"digest":{"function_hash":"280428441958148129571156814309440870815","length":717},"id":"CVE-2026-57076-c295fa34","signature_type":"Function","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"handler.c","function":"syck_hdlr_add_anchor"}},{"deprecated":false,"digest":{"function_hash":"305148560463794313365999651028358570527","length":64},"id":"CVE-2026-57076-c3f27fdb","signature_type":"Function","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"token.c","function":"is_newline"}},{"deprecated":false,"digest":{"line_hashes":["193144376942516510002621782587203254530","201937686965978263800550440870623774226","203672253273203203969964281433636506783","131590351784149087162454638992196898955"],"threshold":0.9},"id":"CVE-2026-57076-cafb559e","signature_type":"Line","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"syck.h"}},{"source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"handler.c","function":"syck_hdlr_get_anchor"},"deprecated":false,"digest":{"function_hash":"309917466370279632901307964742130597888","length":729},"id":"CVE-2026-57076-f2adcc92","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["109053212855870174436396176189900981211","300946420711893109402425648211232915002","29638911357346424521457188108548952138","192378560005233587124998407649124115701","266335857332374648736915778996619725375","202838651893280525781676181030437468404","93108951193344080239107588525837990524","21424171615538297629770193187624320491","269122816966659579176789069150494789890","244931167499514976273330831309963541396","83436258340796675167597066148613154544","5288654962837003661309740242263816603","261214944647090124489559209911243830466","35055014795181382374908324354870731278","104412393083280564705394192148174484791","49606583818967490535859737167257438093","85741250055215155848205138953484762937","153527942865582509621713788832725168782","132491652604768190107541013417097975090","54137758078155853400374694449988983164","2344752180976748474909033712048943825","228148672557870603393015587477694714409","83522940377937147063366070008894363755","325158618193665797873811154571089611476","87089303873712430659997034920275821051","156972829529526034986897405776643680925","277412454261140018516242519943215541304","7273315348423512422097214888473642919","208531449796922786559662225849864162862","246586712308561010065205665361779724495","37645552798907498142638951171216282915","174171239123048514144179204327407483481","208531449796922786559662225849864162862","246586712308561010065205665361779724495","37645552798907498142638951171216282915","174171239123048514144179204327407483481","43634702163297428271096269319957188441","246586712308561010065205665361779724495","37645552798907498142638951171216282915","174171239123048514144179204327407483481","278887732580044443098952995011351229273","280871611499128136538486273764630161076","123787778331115835903055292229274304186","25029778706679110870101451237449647713","234125559471660189616455094751747375325","40830696733819359274871983565139282655","40107068541858419354406976654469456153","17066250442528054019884911912207793325","239416768116013214446971298399330462208","328674700182567586894299065086908351544","164138447335476213796425742173280468283","231907265292910655813869719707095788335","91066956627967611511921508403490515236","135370613682878903101477520987058942486","93914775482248743422415867599087739593","314976323354655568261510984137274938787","188222025935830790450005650743286891465"]},"id":"CVE-2026-57076-f668be84","signature_type":"Line","signature_version":"v1","source":"https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b","target":{"file":"token.c"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}