CVE-2026-75432: Yaml-cpp yaml-cpp vulnerability
Published Sep 22, 2026
·Updated
An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components
Affected Software
1 affected component
yaml-cpp yaml-cpp=0.9.0
Event History
Sep 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Does exploitation require local access?
The issue is described as remotely exploitable. The available information does not state whether authentication, a specific YAML input, or application-level exposure is required.
2
Which release is identified as affected?
The reported affected release is yaml-cpp 0.9.0. No affected version range or fixed release is provided.
3
Is a patch or mitigation specified?
No patch version or workaround is specified in the available information. The references include an upstream issue and pull request, but their resolution status is not provided.