---
id: CVE-2026-75432
title: >-
  An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive
  information via the src/scanner.cpp, Scanner::PopIndent(), and
  Scanner::PushIndentTo() components
summary: >-
  An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive
  information via the src/scanner.cpp, Scanner::PopIndent(), and
  Scanner::PushIndentTo() components
severity: medium
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:17:05.377'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75432'
references:
  - url: 'https://github.com/jbeder/yaml-cpp/issues/1475'
    label: cve@mitre.org
  - url: 'https://github.com/jbeder/yaml-cpp/pull/1476'
    label: cve@mitre.org
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75432.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-75432'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2538741'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-75432'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75432'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ingestedAt: '2026-09-22T20:10:15.099Z'
vendor: Red Hat
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cvssSource: vendor
cwe:
  - CWE-201
epss: 0.00281
epssPercentile: 0.20852
---

## Overview

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-75432.json)
