---
id: CVE-2025-11683
title: >-
  YAML::Syck versions before 1.36 for Perl has missing null-terminators which
  causes out-of-bounds read and potential information disclosure


  Missing null terminators in token.c leads to but-of-bounds read which allows
  adjacent variable to…
summary: >-
  YAML::Syck versions before 1.36 for Perl has missing null-terminators which
  causes out-of-bounds read and potential information disclosure


  Missing null terminators in token.c leads to but-of-bounds read which allows
  adjacent variable to…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-119
vendor: toddr
product: 'yaml::syck'
affected:
  - 'yaml::syck < 1.36'
patched:
  - 'yaml::syck 1.36'
published: '2025-10-16'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11683'
references:
  - url: 'https://github.com/cpan-authors/YAML-Syck/pull/65'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
  - url: 'https://metacpan.org/dist/YAML-Syck/changes'
    label: 9b29abf9-4ab0-4765-b253-1875cd9b441e
tags:
  - nvd
epss: 0.00247
epssPercentile: 0.14637
ingestedAt: '2026-10-08T11:31:27.445Z'
---

## Overview

YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure

Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read

The issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.

## Affected

- `yaml::syck < 1.36`

## Remediation

Upgrade past the affected range:

- `yaml::syck 1.36`
