YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.
In the bundled libsyck newlinelen and isnewline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover.
Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57077.json",
"cna_assigner": "CPANSec",
"cwe_ids": [
"CWE-125"
]
}[
{
"digest": {
"length": 354.0,
"function_hash": "205949390577844048625194730347820491351"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "syck_st_free",
"file": "syck_.c"
},
"id": "CVE-2026-57077-07d6750d",
"deprecated": false
},
{
"digest": {
"length": 1228.0,
"function_hash": "326582959051301847547394615690452582809"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "syck_base64dec",
"file": "emitter.c"
},
"id": "CVE-2026-57077-11b54e13",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"153659563404254961675387871074310784069",
"238603781768247395376034017371589287208",
"194492483442587170580378982103270455711",
"18951947394846091036918930740782989621",
"54883433251445638069494168451322010540",
"56770392230353912212937218086181654062",
"175204374287167279126339530782513813824"
]
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Line",
"target": {
"file": "emitter.c"
},
"id": "CVE-2026-57077-41da57bc",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"294383180027775892745666706312534019452",
"130998452209541435186565716819320512344",
"236647752601270572743049009509140267253",
"119152905233745251099553992089053274191",
"189396070798767280761059661544608526192",
"176734052533153087529477162418257736087",
"251876608254463756416520223451141109766",
"73111910942660763149654038567500359561",
"198909418965871326355592002471057239688",
"66748749295714258781636004316398720563",
"119152905233745251099553992089053274191",
"189396070798767280761059661544608526192",
"176734052533153087529477162418257736087",
"12107093945058425387014483290229305476",
"87048951880703195251423495550003510856",
"29816656809461522764555329716499096230",
"82010664234264932568129467259937814213",
"271089262542772998061079533021026026107",
"10501327679000650957840829582799107777",
"38465091907257408374363037593680334734",
"183455587666296399578388097670965746541"
]
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Line",
"target": {
"file": "handler.c"
},
"id": "CVE-2026-57077-6db7c1df",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"300739074869227694518400055323772669415",
"297565083208233808283691651223099082827",
"26407522250850449308517377679101468492",
"261085206708920514973862133584494079795",
"130026790572182239191042056231752694159",
"263718777400305828631063872972097778935",
"10942217524268166655663490020323927553",
"163496723598585183444973455442679174080",
"308185686592451130514126114284990629249",
"150711256225834430413627958930645429452",
"229384713873150713362683108144110899935",
"213072484150950808188445861800262235123",
"42071503780153570395348125200549668486"
]
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Line",
"target": {
"file": "syck_.c"
},
"id": "CVE-2026-57077-7062aca5",
"deprecated": false
},
{
"digest": {
"length": 38190.0,
"function_hash": "162989237942083865717985892003361415813"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "sycklex_yaml_utf8",
"file": "token.c"
},
"id": "CVE-2026-57077-7ddaac19",
"deprecated": false
},
{
"digest": {
"length": 354.0,
"function_hash": "192005287857108775521087267063681919651"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "syck_hdlr_remove_anchor",
"file": "handler.c"
},
"id": "CVE-2026-57077-8c46914c",
"deprecated": false
},
{
"digest": {
"length": 549.0,
"function_hash": "2513376158406347726063971426490200103"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "syck_new_parser",
"file": "syck_.c"
},
"id": "CVE-2026-57077-9c2962d7",
"deprecated": false
},
{
"digest": {
"length": 164.0,
"function_hash": "275898697991629277122893737114381470555"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "syck_st_free_nodes",
"file": "syck_.c"
},
"id": "CVE-2026-57077-a7deafd4",
"deprecated": false
},
{
"digest": {
"length": 142.0,
"function_hash": "168447789732427871208928294987378522824"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "newline_len",
"file": "token.c"
},
"id": "CVE-2026-57077-c18ffd5d",
"deprecated": false
},
{
"digest": {
"length": 717.0,
"function_hash": "280428441958148129571156814309440870815"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "syck_hdlr_add_anchor",
"file": "handler.c"
},
"id": "CVE-2026-57077-c295fa34",
"deprecated": false
},
{
"digest": {
"length": 64.0,
"function_hash": "305148560463794313365999651028358570527"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "is_newline",
"file": "token.c"
},
"id": "CVE-2026-57077-c3f27fdb",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"193144376942516510002621782587203254530",
"201937686965978263800550440870623774226",
"203672253273203203969964281433636506783",
"131590351784149087162454638992196898955"
]
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Line",
"target": {
"file": "syck.h"
},
"id": "CVE-2026-57077-cafb559e",
"deprecated": false
},
{
"digest": {
"length": 729.0,
"function_hash": "309917466370279632901307964742130597888"
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Function",
"target": {
"function": "syck_hdlr_get_anchor",
"file": "handler.c"
},
"id": "CVE-2026-57077-f2adcc92",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"109053212855870174436396176189900981211",
"300946420711893109402425648211232915002",
"29638911357346424521457188108548952138",
"192378560005233587124998407649124115701",
"266335857332374648736915778996619725375",
"202838651893280525781676181030437468404",
"93108951193344080239107588525837990524",
"21424171615538297629770193187624320491",
"269122816966659579176789069150494789890",
"244931167499514976273330831309963541396",
"83436258340796675167597066148613154544",
"5288654962837003661309740242263816603",
"261214944647090124489559209911243830466",
"35055014795181382374908324354870731278",
"104412393083280564705394192148174484791",
"49606583818967490535859737167257438093",
"85741250055215155848205138953484762937",
"153527942865582509621713788832725168782",
"132491652604768190107541013417097975090",
"54137758078155853400374694449988983164",
"2344752180976748474909033712048943825",
"228148672557870603393015587477694714409",
"83522940377937147063366070008894363755",
"325158618193665797873811154571089611476",
"87089303873712430659997034920275821051",
"156972829529526034986897405776643680925",
"277412454261140018516242519943215541304",
"7273315348423512422097214888473642919",
"208531449796922786559662225849864162862",
"246586712308561010065205665361779724495",
"37645552798907498142638951171216282915",
"174171239123048514144179204327407483481",
"208531449796922786559662225849864162862",
"246586712308561010065205665361779724495",
"37645552798907498142638951171216282915",
"174171239123048514144179204327407483481",
"43634702163297428271096269319957188441",
"246586712308561010065205665361779724495",
"37645552798907498142638951171216282915",
"174171239123048514144179204327407483481",
"278887732580044443098952995011351229273",
"280871611499128136538486273764630161076",
"123787778331115835903055292229274304186",
"25029778706679110870101451237449647713",
"234125559471660189616455094751747375325",
"40830696733819359274871983565139282655",
"40107068541858419354406976654469456153",
"17066250442528054019884911912207793325",
"239416768116013214446971298399330462208",
"328674700182567586894299065086908351544",
"164138447335476213796425742173280468283",
"231907265292910655813869719707095788335",
"91066956627967611511921508403490515236",
"135370613682878903101477520987058942486",
"93914775482248743422415867599087739593",
"314976323354655568261510984137274938787",
"188222025935830790450005650743286891465"
]
},
"signature_version": "v1",
"source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
"signature_type": "Line",
"target": {
"file": "token.c"
},
"id": "CVE-2026-57077-f668be84",
"deprecated": false
}
]
"2026-07-22T04:28:34Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57077.json"