Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read
The issue is seen with complex YAML files with a hash of all keys and empty values. There is no indication that the issue leads to accessing memory outside that allocated to the module.
Project Subscriptions
No advisories yet.
Solution
Upgrade to version 1.36 or higher
Workaround
Apply the patch
Mon, 09 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toddr
Toddr yaml\ |
|
| CPEs | cpe:2.3:a:toddr:yaml\:\:syck:*:*:*:*:*:perl:*:* | |
| Vendors & Products |
Toddr
Toddr yaml\ |
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perl
Perl perl Perl yaml::syck |
|
| Vendors & Products |
Perl
Perl perl Perl yaml::syck |
Fri, 17 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 16 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 16 Oct 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a hash of all keys and empty values. There is no indication that the issue leads to accessing memory outside that allocated to the module. | |
| Title | YAML::Syck versions before 1.36 for Perl has missing Null-Terminators which causes Out-of-Bounds Read and potential Information Disclosure | |
| Weaknesses | CWE-119 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2025-10-16T13:42:17.584Z
Reserved: 2025-10-13T12:35:07.822Z
Link: CVE-2025-11683
Updated: 2025-10-16T13:42:05.706Z
Status : Analyzed
Published: 2025-10-16T01:15:32.890
Modified: 2026-03-09T15:05:36.383
Link: CVE-2025-11683
OpenCVE Enrichment
Updated: 2025-10-21T09:40:49Z