CVE-2026-57076

EUVD-2026-45055
YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor.

In the bundled libsyck an anchor name allocated by syck_strndup is stored both as node->anchor, freed when the node is freed, and as the key in the parser's anchors table. Freeing the node frees the shared key, and a later anchor redefinition makes st_delete compare against the freed key, so st_strcmp reads freed heap memory. Anchors are a standard YAML feature and need no special flags, so this is reached on the default Load path.

Any caller that runs Load or LoadFile on an untrusted document that redefines an anchor reaches the read of freed memory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.46%
Debian logo
Debian Releases
Debian Product
Codename
libyaml-syck-perl
bookworm
vulnerable
bookworm (security)
1.34-2+deb12u3
fixed
bullseye
vulnerable
bullseye (security)
1.34-1+deb11u2
fixed
forky
1.47-1
fixed
sid
1.47-1
fixed
trixie
vulnerable
trixie (security)
1.34-2+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libyaml-syck-perl
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-YAML-Syck
Amazon Linux 2
0:1.27-3.amzn2.0.6
fixed
Amazon Linux 2023
0:1.37-1.amzn2023.0.4
fixed
perl-YAML-Syck-debuginfo
Amazon Linux 2
0:1.27-3.amzn2.0.6
fixed
Amazon Linux 2023
0:1.37-1.amzn2023.0.4
fixed
perl-YAML-Syck-debugsource
Amazon Linux 2023
0:1.37-1.amzn2023.0.4
fixed
perl-YAML-Syck-tests
Amazon Linux 2023
0:1.37-1.amzn2023.0.4
fixed