{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "1.27_001"
              }
            ],
            "source": [
              "DESCRIPTION",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "b3c7869c21e7f71364394b817b55cae46fd74fa8"
            },
            {
              "fixed": "bace96b5e6661d521c7c515c94a09e081c911fce"
            }
          ],
          "repo": "https://github.com/ingydotnet/yaml-pm",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {},
  "details": "YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution.\n\nA perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options.\n\nA perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code.",
  "id": "CVE-2019-25777",
  "modified": "2026-10-08T02:30:27.029355102Z",
  "published": "2026-10-05T07:16:29.557Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/10/05/7"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/TINITA/YAML-1.28/changes"
    },
    {
      "type": "REPORT",
      "url": "https://github.com/ingydotnet/yaml-pm/issues/212"
    },
    {
      "type": "FIX",
      "url": "https://github.com/ingydotnet/yaml-pm/commit/bace96b5e6661d521c7c515c94a09e081c911fce.patch"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
      "type": "CVSS_V3"
    }
  ]
}