https://seclists.org/oss-sec/2026/q3/159: CVE-2026-57075: YAML::Syck versions befo1.47 for Perl allow an out-of-bounds ad via a signed-char lookup-table index in syck_base64dec
Published Jul 16, 2026
·Updated
Affected Software
1 affected component
CPAN YAML::Syck<1.47
Frequently Asked Questions
1
What is the severity of CVE-2026-57075?
CVE-2026-57075 is classified as a critical vulnerability due to its potential for out-of-bounds write exploitation.
2
How do I fix CVE-2026-57075?
To fix CVE-2026-57075, upgrade to YAML::Syck version 1.47 or later.
3
What software is affected by CVE-2026-57075?
CVE-2026-57075 affects the CPAN YAML::Syck versions before 1.47.
4
What type of vulnerability is CVE-2026-57075?
CVE-2026-57075 is an out-of-bounds access vulnerability affecting YAML::Syck in Perl.
5
When was CVE-2026-57075 published?
CVE-2026-57075 was published on July 16, 2026.