Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <2368EA95-062D-454F-88D1-1A0CC4BF29B1@stig.io>
Date: Mon, 5 Oct 2026 08:51:56 +0200
From: Stig Palmquist <stig@...g.io>
To: cve-announce@...urity.metacpan.org,
 oss-security@...ts.openwall.com
Subject: CVE-2019-25777: YAML versions before 1.27_001 for Perl allow a loaded
 perl/glob document to replace any package variable, which can lead to
 arbitrary code execution 

========================================================================
CVE-2019-25777                                       CPAN Security Group
========================================================================

        CVE ID:  CVE-2019-25777

  Distribution:  YAML
      Versions:  before 1.27_001
      MetaCPAN:  https://metacpan.org/dist/YAML
      VCS Repo:  https://github.com/ingydotnet/yaml-pm


YAML versions before 1.27_001 for Perl allow a loaded perl/glob
document to replace any package variable, which can lead to arbitrary
code execution

Description
-----------
YAML versions before 1.27_001 for Perl allow a loaded perl/glob
document to replace any package variable, which can lead to arbitrary
code execution.

A perl/glob document names a package and a symbol, and supplies the
value assigned to it. Nothing restricts the name, so the target can be
@INC or YAML's own load options.

A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns
on code loading, which is off by default, for every later Load() in the
process. A perl/code document is then passed to a string eval, so an
attacker who supplies two documents to separate Load() calls in one
process can execute arbitrary Perl code.

Problem types
-------------
- CWE-914 Improper Control of Dynamically-Identified Variables
- CWE-502 Deserialization of Untrusted Data

Workarounds
-----------
For deployments that cannot upgrade to YAML 1.28, set
$YAML::LoadBlessed = 0 before loading untrusted input. The option
exists from YAML 1.25 and gates glob loading too.

Solutions
---------
Upgrade to YAML 1.28 or later.

References
----------
https://github.com/ingydotnet/yaml-pm/issues/212
https://github.com/ingydotnet/yaml-pm/commit/bace96b5e6661d521c7c515c94a09e081c911fce.patch
https://metacpan.org/release/TINITA/YAML-1.28/changes

Timeline
--------
- 2019-04-27: Issue reported.
- 2019-04-27: Version 1.27_001 released with fix.
- 2019-04-28: Version 1.28 released with fix.
- 2022-06-27: Issue added as CPANSA-YAML-2019-01 in the CPAN::Audit
  database.
- 2026-09-21: CVE number reserved.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.