Heap-based Buffer Overflow Affecting cpan-authors/YAML-Syck package, versions [,1.37-01)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.43% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Heap-based Buffer Overflow vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-CPANAUTHORSYAMLSYCK-15758258
  • published23 Mar 2026
  • disclosed17 Mar 2026
  • creditUnknown

Introduced: 17 Mar 2026

CVE-2026-4177  (opens in a new tab)
CWE-122  (opens in a new tab)

How to fix?

Upgrade cpan-authors/YAML-Syck to version 1.37-01 or higher.

Overview

Affected versions of this package are vulnerable to Heap-based Buffer Overflow via the strcat(tag, ref) with long class names. An attacker can cause a heap buffer overflow by providing class names that exceed the initial allocation size, potentially leading to memory corruption or application crash. Additional issues include the base64 decoder reading past the buffer end on trailing newlines, mutation of n->type_id in place by strtok which can corrupt shared node data, and a memory leak in syck_hdlr_add_anchor when a node already has an anchor.

References

CVSS Base Scores

version 4.0
version 3.1