Yves maintains a narrow vulnerability footprint centered on Sereal, a serialization library used in data-handling contexts where deserialization safety is critical. The recurring exposure involves out-of-bounds write conditions, a structural weakness in parsing and memory-management logic that warrants careful review during integration and upgrade cycles. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yves over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8796HIGH Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input.
In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY | May 31, 2026 | 8.1 | 34 | NO | NO |
CVE-2024-14031HIGH Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library.
Sereal::Encoder embeds a version of the Zstandard (zstd) libra | Mar 31, 2026 | 8.1 | 27 | NO | NO |
CVE-2024-14030HIGH Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library.
Sereal::Decoder embeds a version of the Zstandard (zstd) libra | Mar 31, 2026 | 8.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yves.
Media articles that mention a CVE ID that affects a product developed by Yves — matched by CVE ID, not by vendor name.