#1149048 yaml-cpp: CVE-2026-75432

Package:
src:yaml-cpp
Source:
src:yaml-cpp
Submitter:
Salvatore Bonaccorso
Date:
2026-09-26 18:49:02 UTC
Severity:
normal
Tags:
#1149048#5
Date:
2026-09-26 11:12:36 UTC
From:
To:
Hi,

The following vulnerability was published for yaml-cpp.

CVE-2026-75432[0]:
| An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain
| sensitive information via the src/scanner.cpp, Scanner::PopIndent(),
| and Scanner::PushIndentTo() components


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-75432
https://www.cve.org/CVERecord?id=CVE-2026-75432
[1] https://github.com/jbeder/yaml-cpp/issues/1475
[2] https://github.com/jbeder/yaml-cpp/pull/1476
[3] https://github.com/jbeder/yaml-cpp/commit/8b2e6ba3288de15ed7a61d5c89cde2ed47327c1e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149048#10
Date:
2026-09-26 15:05:21 UTC
From:
To:
Hi Salvatore,

Please mark yaml-cpp <not-affected> for bookworm, trixie, and sid. No upload is planned.

The crash is an empty indent-stack pop in Scanner::PopIndent(). Upstream introduced it in c7a86c0 (PR #1468, 2026-07-30), *after* the yaml-cpp-0.9.0 tag (56e3bb5, 2026-02-04). That commit is not in the 0.9.0 tarball.

I ran the public inputs against the archive versions:

   bookworm  0.7.0+dfsg-8+b1   ParserException (the 96-byte sample parses)
   trixie    0.8.0+dfsg-7      ParserException
   sid       0.9.0+dfsg-9      ParserException

None of them abort. Those inputs do abort on upstream 3eb39d5, which is after #1468 and before #1476: UndefinedBehaviorSanitizer in PopIndent(), and SIGSEGV.

The MITRE text describes an information leak in 0.9.0. What reproduces is a crash on master snapshots from 30 July to 10 August 2026. No Debian suite is in that window.

Please let me know if you have any questions, or if this still needs to be fixed after all.

Best regards,
Simon Quigley
tsimonq2@debian.org

#1149048#15
Date:
2026-09-26 18:47:20 UTC
From:
To:
Hi Simon,

Yes, agreed, the issue is introduced with
https://github.com/jbeder/yaml-cpp/commit/c7a86c0e1f4868abebab474a6a3e19cf27ebfaac
, so I have updated the tracker information on the CVE.

Regards,
Salvatore