Toddr's vulnerability profile concentrates on data serialization and markup parsing, specifically affecting its XML and YAML processing components. The observed weakness classes—heap-based buffer overflows, unicode encoding handling defects, memory-boundary violations, and off-by-one errors—reflect the memory-safety challenges inherent to parsing untrusted data formats. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Toddr over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57075CRITICAL YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec.
The base64 decoder in the bundled libsyck indexes the | Jul 16, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-57076HIGH YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor.
In the bundled libsyck an anchor na | Jul 16, 2026 | 7.8 | 36 | NO | NO |
CVE-2026-57077HIGH YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len.
In the bundled libsyck newline_len and is_newline dereference th | Jul 16, 2026 | 7.7 | 35 | NO | NO |
CVE-2006-10003CRITICAL XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack.
In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then | Mar 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-4177CRITICAL YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.
The heap overflow occu | Mar 16, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-13713MEDIUM YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack.
In the bundled libsyck, when an anc | Jul 16, 2026 | 6.2 | 31 | NO | NO |
CVE-2026-5089HIGH YAML::Syck versions before 1.38 for Perl has an out-of-bounds read.
The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#b | May 12, 2026 | 7.3 | 29 | NO | NO |
CVE-2006-10002HIGH XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes.
A :utf8 PerlIO layer, pars | Mar 19, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-11683MEDIUM YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure
Missing null terminators in token.c lead | Oct 16, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toddr.
Media articles that mention a CVE ID that affects a product developed by Toddr — matched by CVE ID, not by vendor name.