CVE-2026-57077

Source
https://cve.org/CVERecord?id=CVE-2026-57077
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57077.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-57077
Downstream
Related
Published
2026-07-16T21:41:52.038Z
Modified
2026-07-22T04:28:34.407336Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len
Details

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.

In the bundled libsyck newlinelen and isnewline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover.

Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57077.json",
    "cna_assigner": "CPANSec",
    "cwe_ids": [
        "CWE-125"
    ]
}
References

Affected packages

Git / github.com/cpan-authors/YAML-Syck

Affected ranges

Type
GIT
Repo
https://github.com/cpan-authors/YAML-Syck
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.47"
        }
    ]
}

Affected versions

0.*
0.01
0.02
0.03
0.04
0.05
0.06
0.07
0.08
0.09
0.10
0.11
0.12
0.13
0.14
0.15
0.16
0.17
0.18
0.19
0.20
0.21
0.22
0.23
0.24
0.25
0.26
0.27
0.28
0.29
0.30
0.31
0.32
0.33
0.34
0.35
0.36
0.37
0.38
0.40
0.41
0.42
0.43
0.44
0.45
0.46_01
0.60
0.61
0.62
0.63
0.64
0.65
0.66
0.67
0.70
0.71
0.72
0.80
0.81
0.82
0.84
0.85
0.86
0.87
0.88
0.90
0.91
0.94
0.95
0.96
0.97
0.98
0.99
1.*
1.00
1.01
1.02
1.03
1.04
1.05
1.07
1.07_01
1.08
1.08_01
1.09
1.10
1.10_01
1.10_02
1.10_03
1.10_04
1.10_05
1.10_06
1.10_07
1.11
1.12
1.13
1.14
1.15
1.20
1.21_01
1.22
1.23
1.24_01
1.24_02
1.26
1.27
1.28
1.28_01
1.29_01
1.30
1.30_01
1.31
1.32
1.33
1.34
1.35
1.36
1.37
1.37_01
1.38
1.39
1.41
1.42
1.43
1.44
1.45
1.46
v1.*
v1.28
v1.28_01
v1.29_01
v1.30
v1.30_01
v1.31
v1.32
v1.33
v1.34
v1.35
v1.36

Database specific

vanir_signatures
[
    {
        "digest": {
            "length": 354.0,
            "function_hash": "205949390577844048625194730347820491351"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "syck_st_free",
            "file": "syck_.c"
        },
        "id": "CVE-2026-57077-07d6750d",
        "deprecated": false
    },
    {
        "digest": {
            "length": 1228.0,
            "function_hash": "326582959051301847547394615690452582809"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "syck_base64dec",
            "file": "emitter.c"
        },
        "id": "CVE-2026-57077-11b54e13",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "153659563404254961675387871074310784069",
                "238603781768247395376034017371589287208",
                "194492483442587170580378982103270455711",
                "18951947394846091036918930740782989621",
                "54883433251445638069494168451322010540",
                "56770392230353912212937218086181654062",
                "175204374287167279126339530782513813824"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Line",
        "target": {
            "file": "emitter.c"
        },
        "id": "CVE-2026-57077-41da57bc",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "294383180027775892745666706312534019452",
                "130998452209541435186565716819320512344",
                "236647752601270572743049009509140267253",
                "119152905233745251099553992089053274191",
                "189396070798767280761059661544608526192",
                "176734052533153087529477162418257736087",
                "251876608254463756416520223451141109766",
                "73111910942660763149654038567500359561",
                "198909418965871326355592002471057239688",
                "66748749295714258781636004316398720563",
                "119152905233745251099553992089053274191",
                "189396070798767280761059661544608526192",
                "176734052533153087529477162418257736087",
                "12107093945058425387014483290229305476",
                "87048951880703195251423495550003510856",
                "29816656809461522764555329716499096230",
                "82010664234264932568129467259937814213",
                "271089262542772998061079533021026026107",
                "10501327679000650957840829582799107777",
                "38465091907257408374363037593680334734",
                "183455587666296399578388097670965746541"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Line",
        "target": {
            "file": "handler.c"
        },
        "id": "CVE-2026-57077-6db7c1df",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "300739074869227694518400055323772669415",
                "297565083208233808283691651223099082827",
                "26407522250850449308517377679101468492",
                "261085206708920514973862133584494079795",
                "130026790572182239191042056231752694159",
                "263718777400305828631063872972097778935",
                "10942217524268166655663490020323927553",
                "163496723598585183444973455442679174080",
                "308185686592451130514126114284990629249",
                "150711256225834430413627958930645429452",
                "229384713873150713362683108144110899935",
                "213072484150950808188445861800262235123",
                "42071503780153570395348125200549668486"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Line",
        "target": {
            "file": "syck_.c"
        },
        "id": "CVE-2026-57077-7062aca5",
        "deprecated": false
    },
    {
        "digest": {
            "length": 38190.0,
            "function_hash": "162989237942083865717985892003361415813"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "sycklex_yaml_utf8",
            "file": "token.c"
        },
        "id": "CVE-2026-57077-7ddaac19",
        "deprecated": false
    },
    {
        "digest": {
            "length": 354.0,
            "function_hash": "192005287857108775521087267063681919651"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "syck_hdlr_remove_anchor",
            "file": "handler.c"
        },
        "id": "CVE-2026-57077-8c46914c",
        "deprecated": false
    },
    {
        "digest": {
            "length": 549.0,
            "function_hash": "2513376158406347726063971426490200103"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "syck_new_parser",
            "file": "syck_.c"
        },
        "id": "CVE-2026-57077-9c2962d7",
        "deprecated": false
    },
    {
        "digest": {
            "length": 164.0,
            "function_hash": "275898697991629277122893737114381470555"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "syck_st_free_nodes",
            "file": "syck_.c"
        },
        "id": "CVE-2026-57077-a7deafd4",
        "deprecated": false
    },
    {
        "digest": {
            "length": 142.0,
            "function_hash": "168447789732427871208928294987378522824"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "newline_len",
            "file": "token.c"
        },
        "id": "CVE-2026-57077-c18ffd5d",
        "deprecated": false
    },
    {
        "digest": {
            "length": 717.0,
            "function_hash": "280428441958148129571156814309440870815"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "syck_hdlr_add_anchor",
            "file": "handler.c"
        },
        "id": "CVE-2026-57077-c295fa34",
        "deprecated": false
    },
    {
        "digest": {
            "length": 64.0,
            "function_hash": "305148560463794313365999651028358570527"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "is_newline",
            "file": "token.c"
        },
        "id": "CVE-2026-57077-c3f27fdb",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "193144376942516510002621782587203254530",
                "201937686965978263800550440870623774226",
                "203672253273203203969964281433636506783",
                "131590351784149087162454638992196898955"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Line",
        "target": {
            "file": "syck.h"
        },
        "id": "CVE-2026-57077-cafb559e",
        "deprecated": false
    },
    {
        "digest": {
            "length": 729.0,
            "function_hash": "309917466370279632901307964742130597888"
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Function",
        "target": {
            "function": "syck_hdlr_get_anchor",
            "file": "handler.c"
        },
        "id": "CVE-2026-57077-f2adcc92",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "109053212855870174436396176189900981211",
                "300946420711893109402425648211232915002",
                "29638911357346424521457188108548952138",
                "192378560005233587124998407649124115701",
                "266335857332374648736915778996619725375",
                "202838651893280525781676181030437468404",
                "93108951193344080239107588525837990524",
                "21424171615538297629770193187624320491",
                "269122816966659579176789069150494789890",
                "244931167499514976273330831309963541396",
                "83436258340796675167597066148613154544",
                "5288654962837003661309740242263816603",
                "261214944647090124489559209911243830466",
                "35055014795181382374908324354870731278",
                "104412393083280564705394192148174484791",
                "49606583818967490535859737167257438093",
                "85741250055215155848205138953484762937",
                "153527942865582509621713788832725168782",
                "132491652604768190107541013417097975090",
                "54137758078155853400374694449988983164",
                "2344752180976748474909033712048943825",
                "228148672557870603393015587477694714409",
                "83522940377937147063366070008894363755",
                "325158618193665797873811154571089611476",
                "87089303873712430659997034920275821051",
                "156972829529526034986897405776643680925",
                "277412454261140018516242519943215541304",
                "7273315348423512422097214888473642919",
                "208531449796922786559662225849864162862",
                "246586712308561010065205665361779724495",
                "37645552798907498142638951171216282915",
                "174171239123048514144179204327407483481",
                "208531449796922786559662225849864162862",
                "246586712308561010065205665361779724495",
                "37645552798907498142638951171216282915",
                "174171239123048514144179204327407483481",
                "43634702163297428271096269319957188441",
                "246586712308561010065205665361779724495",
                "37645552798907498142638951171216282915",
                "174171239123048514144179204327407483481",
                "278887732580044443098952995011351229273",
                "280871611499128136538486273764630161076",
                "123787778331115835903055292229274304186",
                "25029778706679110870101451237449647713",
                "234125559471660189616455094751747375325",
                "40830696733819359274871983565139282655",
                "40107068541858419354406976654469456153",
                "17066250442528054019884911912207793325",
                "239416768116013214446971298399330462208",
                "328674700182567586894299065086908351544",
                "164138447335476213796425742173280468283",
                "231907265292910655813869719707095788335",
                "91066956627967611511921508403490515236",
                "135370613682878903101477520987058942486",
                "93914775482248743422415867599087739593",
                "314976323354655568261510984137274938787",
                "188222025935830790450005650743286891465"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/cpan-authors/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b",
        "signature_type": "Line",
        "target": {
            "file": "token.c"
        },
        "id": "CVE-2026-57077-f668be84",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-22T04:28:34Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57077.json"