CVE-2026-4177 is a critical vulnerability affecting YAML::Syck versions through 1.36 for Perl, primarily a high-severity heap buffer overflow in the YAML emitter, alongside other issues like memory leaks. Rated 9.1 CVSS (Critical), it allows unauthenticated attackers to achieve high confidentiality and availability impacts via low-complexity network attacks. Despite its severity, there is no evidence of active exploitation, public exploit code, or significant community attention, and it is not present on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.37CPE matchmatch criteria | cpe:2.3:a:toddr:yaml\:\:syck:*:*:*:*:*:perl:*:* | ||
>= 0, <= 1.36CPE match | cpe:2.3:a:toddr:yaml\:\:syck:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.