CVE-2026-5089

NameCVE-2026-5089
DescriptionYAML::Syck versions before 1.38 for Perl has an out-of-bounds read. ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libyaml-syck-perl (PTS)bullseye1.34-1vulnerable
bullseye (security)1.34-1+deb11u1vulnerable
bookworm1.34-2+deb12u1vulnerable
bookworm (security)1.34-2+deb12u2vulnerable
trixie1.34-2+deb13u1vulnerable
trixie (security)1.34-2+deb13u2vulnerable
forky1.36-2vulnerable
sid1.36-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libyaml-syck-perlsource(unstable)1.36-3

Notes

https://lists.security.metacpan.org/cve-announce/msg/39981051/
https://github.com/cpan-authors/YAML-Syck/issues/132
https://github.com/cpan-authors/YAML-Syck/pull/133
Fixed by: https://github.com/cpan-authors/YAML-Syck/commit/208a4d3bd1b5cdb4a791a6e3905bd6bd45e9d005 (1.38)

Search for package or bug name: Reporting problems