CVE-2026-57075 Affecting libyaml-syck-perl package, versions <1.34-2+deb13u3


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.37% (30th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-LIBYAMLSYCKPERL-18003164
  • published17 Jul 2026
  • disclosed16 Jul 2026

Introduced: 16 Jul 2026

NewCVE-2026-57075  (opens in a new tab)

How to fix?

Upgrade Debian:13 libyaml-syck-perl to version 1.34-2+deb13u3 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libyaml-syck-perl package and not the libyaml-syck-perl package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.

The base64 decoder in the bundled libsyck indexes the 256-entry static table b64_xtable with a signed char, so any !!binary byte >= 0x80 sign-extends to a negative index and reads before the table. The decoder receives the raw bytes of any !!binary node, a standard YAML type not gated by $LoadBlessed or $LoadCode, so it is reached on the default Load path.

Any caller that runs Load or LoadFile on an untrusted document containing a !!binary scalar with a high-bit byte triggers the read, and the value read can surface in the decoded result.

CVSS Base Scores

version 3.1