CVE-2026-5089Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a colon-separated value (e.g., the 1 in 1:30:45), the inner while loop can decrement a pointer past the start of the string buffer: while ( colon >= ptr && *colon != ':' ) { colon--; } if ( *colon == ':' ) *colon = '\0'; // colon may be ptr-1 here When no colon is found (final/leftmost segment), colon becomes ptr-1, and the subsequent *colon dereference reads one byte before the allocated buffer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-124

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-15: 2Technical Details · 2026-05-15: 205-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-5089: YAML::Syck before 1.38 has an out-of-bounds read https://www.openwall.com/lists/oss-security/2026/05/12/16 CVE-2026-8463: Crypt::Argon2 from 0.017 before 0.031 perform a heap out-of-bounds read in argon2_verify on empty encoded input https://www.openwall.com/lists/oss-security/2026/05/13/4

    Post summary

    Two CVEs (YAML::Syck and Crypt::Argon2) are disclosed as causing out‑of‑bounds read vulnerabilities, with links to advisories but no PoC, exploit or patch details.

    10000167
    4.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-5089: YAML::Syck before 1.38 has an out-of-bounds read https://www.openwall.com/lists/oss-security/2026/05/12/16 CVE-2026-8463: Crypt::Argon2 from 0.017 before 0.031 perform a heap out-of-bounds read in argon2_verify on empty encoded input https://www.openwall.com/lists/oss-security/2026/05/13/4

    Post summary

    The text announces CVE‑2026‑5089 and CVE‑2026‑8463 as out-of-bounds read vulnerabilities in Perl CPAN modules YAML::Syck and Crypt::Argon2, providing technical specifics without revealing PoC, exploit, or remediation details.

    1000049
    4.6K followersView on X

Explore more