SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-13713

MEDIUM · CVSS 6.2 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

YAML::Syck versions prior to 1.47 for Perl are vulnerable to a use-after-free and double-free issue, which occurs when an anchor node is redefined or removed while still on the parser's value stack. This flaw can lead to a denial of service, causing the interpreter to crash when processing untrusted documents that manipulate anchor definitions. Organizations using YAML::Syck in their Perl applications should prioritize updating to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-13713
Severity
MEDIUM
CVSS
6.2
EPSS
0.13%

Original NVD Description

YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node stored under that name with syck_free_node. That node can still be live on the parser's value stack, so syck_hdlr_add_node reaches it again and frees it a second time. On a normal build the 48-byte node chunk is freed twice and the interpreter aborts. Anchors need no special flags, so this is reached on the default Load path, and a 7-byte document that redefines an anchor triggers it. Any caller that runs Load or LoadFile on an untrusted document that redefines an anchor mid-parse crashes the interpreter, a denial of service.