CVE-2026-57076: YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor
YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syckhdlraddanchor.
In the bundled libsyck an anchor name allocated by syckstrndup is stored both as node->anchor, freed when the node is freed, and as the key in the parser's anchors table. Freeing the node frees the shared key, and a later anchor redefinition makes stdelete compare against the freed key, so ststrcmp reads freed heap memory. Anchors are a standard YAML feature and need no special flags, so this is reached on the default Load path.
Any caller that runs Load or LoadFile on an untrusted document that redefines an anchor reaches the read of freed memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Perl YAML::Syckto a version that resolves this vulnerability.Fixed in 1.47 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2026-57076
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57076?
CVE-2026-57076 has a risk rating of 48.
How do I fix CVE-2026-57076?
To fix CVE-2026-57076, upgrade to YAML::Syck version 1.47 or later.
What systems are affected by CVE-2026-57076?
CVE-2026-57076 affects all versions of YAML::Syck for Perl prior to 1.47.
What type of vulnerability is CVE-2026-57076?
CVE-2026-57076 is categorized as a use-after-free vulnerability.
What impact does CVE-2026-57076 have?
CVE-2026-57076 could lead to security risks such as arbitrary code execution due to a heap use-after-free.