OESA-2026-3239

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3239
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3239.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3239
Upstream
  • CVE-2026-63676
Published
2026-08-07T09:19:43Z
Modified
2026-08-18T01:21:27.394722026Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L CVSS Calculator
Summary
perl-YAML security update
Details

The YAML.pm module implements a YAML Loader and Dumper based on the YAML 1.0 specification. http://www.yaml.org/spec/ YAML is a generic data serialization language that is optimized for human readability.It can be used to express the data structures of most modern programming languages. (Including Perl!!!) For information on the YAML syntax, please refer to the YAML specification.

Security Fix(es):

The MPG WordPress plugin prior to 4.1.8 does not sanitize and escape parameters before reflecting them back into the response, allowing an unauthenticated attacker to perform reflected cross-site scripting against a victim who is induced to send a crafted request.(CVE-2026-63676)

Database specific
{
    "severity": "Low"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / perl-YAML

Package

Name
perl-YAML
Purl
pkg:rpm/openEuler/perl-YAML&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.321-1.oe2403sp3

Ecosystem specific

{
    "src": [
        "perl-YAML-1.321-1.oe2403sp3.src.rpm"
    ],
    "noarch": [
        "perl-YAML-1.321-1.oe2403sp3.noarch.rpm",
        "perl-YAML-help-1.321-1.oe2403sp3.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3239.json"