{"id":"CVE-2025-11683","title":"YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure\n\nMissing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to…","summary":"YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure\n\nMissing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-119"],"vendor":"toddr","product":"yaml::syck","affected":["yaml::syck < 1.36"],"patched":["yaml::syck 1.36"],"published":"2025-10-16","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11683","references":[{"url":"https://github.com/cpan-authors/YAML-Syck/pull/65","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/dist/YAML-Syck/changes","label":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"tags":["nvd"],"epss":0.00247,"epssPercentile":0.14653,"ingestedAt":"2026-10-08T11:31:27.445Z","slug":"CVE-2025-11683","body":"## Overview\n\nYAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure\n\nMissing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read\n\nThe issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.\n\n## Affected\n\n- `yaml::syck < 1.36`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `yaml::syck 1.36`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}