{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2019-25777","assignerOrgId":"9b29abf9-4ab0-4765-b253-1875cd9b441e","state":"PUBLISHED","assignerShortName":"CPANSec","dateReserved":"2026-09-21T21:17:21.642Z","datePublished":"2026-10-05T06:50:17.532Z","dateUpdated":"2026-10-06T16:58:19.261Z"},"containers":{"cna":{"affected":[{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","modules":["YAML"],"packageName":"YAML","packageURL":"pkg:cpan/YAML","programFiles":["lib/YAML/Types.pm"],"programRoutines":[{"name":"YAML::Type::glob::yaml_load"}],"repo":"https://github.com/ingydotnet/yaml-pm","versions":[{"lessThan":"1.27_001","status":"affected","version":"0","versionType":"custom"}]}],"descriptions":[{"lang":"en","value":"YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution.\n\nA perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options.\n\nA perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is then passed to a string eval, so an attacker who supplies two documents to separate Load() calls in one process can execute arbitrary Perl code."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-914","description":"CWE-914 Improper Control of Dynamically-Identified Variables","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9b29abf9-4ab0-4765-b253-1875cd9b441e","shortName":"CPANSec","dateUpdated":"2026-10-05T06:50:17.532Z"},"references":[{"tags":["issue-tracking"],"url":"https://github.com/ingydotnet/yaml-pm/issues/212"},{"tags":["patch"],"url":"https://github.com/ingydotnet/yaml-pm/commit/bace96b5e6661d521c7c515c94a09e081c911fce.patch"},{"tags":["release-notes"],"url":"https://metacpan.org/release/TINITA/YAML-1.28/changes"}],"solutions":[{"lang":"en","value":"Upgrade to YAML 1.28 or later."}],"source":{"discovery":"UNKNOWN"},"timeline":[{"lang":"en","time":"2019-04-27T00:00:00.000Z","value":"Issue reported."},{"lang":"en","time":"2019-04-27T00:00:00.000Z","value":"Version 1.27_001 released with fix."},{"lang":"en","time":"2019-04-28T00:00:00.000Z","value":"Version 1.28 released with fix."},{"lang":"en","time":"2022-06-27T00:00:00.000Z","value":"Issue added as CPANSA-YAML-2019-01 in the CPAN::Audit database."},{"lang":"en","time":"2026-09-21T00:00:00.000Z","value":"CVE number reserved."}],"title":"YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution","workarounds":[{"lang":"en","value":"For deployments that cannot upgrade to YAML 1.28, set $YAML::LoadBlessed = 0 before loading untrusted input. The option exists from YAML 1.25 and gates glob loading too."}],"x_generator":{"engine":"cpansec-cna-tool 0.1"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/10/05/7"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-10-05T18:10:19.164Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.3,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","integrityImpact":"LOW","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"LOW","privilegesRequired":"NONE","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-10-06T16:58:07.558999Z","id":"CVE-2019-25777","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-06T16:58:19.261Z"}}]}}