Ingy's vulnerability footprint centers on its YAML serialization libraries and related tooling, which see broad adoption in configuration and data-handling pipelines despite a narrow product scope. The durable signal reflects the inherent risks of code injection and format-string handling in dynamic language implementations, particularly where YAML parsing interfaces with untrusted input streams. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ingy over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6143HIGH Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, wh | Jun 4, 2014 | 7.5 | 25 | NO | NO |
CVE-2012-1152MEDIUM Multiple format string vulnerabilities in the error reporting functionality in the YAML::LibYAML (aka YAML-LibYAML and perl-YAML-LibYAML) module 0.38 for Perl allow remote attacker | Sep 9, 2012 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ingy.
Media articles that mention a CVE ID that affects a product developed by Ingy — matched by CVE ID, not by vendor name.