Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | LibfyamlAI | 24/9/2026 | 25/9/2026 | libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until… | |
| Pendiente de análisis | Sin puntuar | 0.22% | — | Yaml-cppAI | 22/9/2026 | 24/9/2026 | An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components | |
| Aplazada | Alta (7.5) | 1.2% | — | Microsoft Openapi YamlreaderAIMicrosoft Openapi ReadersAI | 8/9/2026 | 10/9/2026 | In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader APIs. YAML is… | |
| Aplazada | Alta (7.5) | 0.54% | — | Nodeca Js-yamlAI | 1/9/2026 | 28/9/2026 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2, 4.3.2, and 5.4.1, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into many merge targets, causing O(N *… | |
| Aplazada | Alta (8.7) | 0.68% | — | ModelscopeAIPyyamlAI | 1/9/2026 | 8/9/2026 | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users. | |
| Aplazada | Alta (8.4) | 0.22% | — | Cgauge YamlAI | 20/8/2026 | 24/9/2026 | @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct callback unconditionally calls eval() on attacker-supplied string values during document parsing. Any application parsing untrusted YAML… | |
| Aplazada | Alta (7.5) | 0.49% | — | Nodeca Js-yamlAI | 13/8/2026 | 18/9/2026 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls load() or loadAll() on untrusted input. In src/parser/parser.ts, readFlowCollection uses restoreState and calls parseNode a second time when a flow-sequence entry is… | |
| Aplazada | Alta (7.7) | 0.19% | — | Yaml SyckAI | 16/7/2026 | 17/7/2026 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document… | |
| Aplazada | Alta (7.8) | 0.17% | — | Yaml SyckAIPerl Yaml SyckAI | 16/7/2026 | 17/7/2026 | YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor. In the bundled libsyck an anchor name allocated by syck_strndup is stored both as node->anchor, freed when the node is freed, and as the key in the parser's anchors table.… | |
| Aplazada | Crítica (9.1) | 0.63% | — | Yaml SyckAI | 16/7/2026 | 17/7/2026 | YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes the 256-entry static table b64_xtable with a signed char, so any !!binary byte >= 0x80 sign-extends to a negative index and reads before the… | |
| Aplazada | Media (6.2) | 0.13% | — | Yaml SyckAIPerlAI | 16/7/2026 | 17/7/2026 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the bundled libsyck, when an anchor name is redefined or removed, syck_hdlr_add_anchor and syck_hdlr_remove_anchor free the node stored under that name with syck_free_node.… | |
| Aplazada | Alta (8.3) | 0.40% | — | HedgedocAINodeca Js-yamlAI | 13/7/2026 | 14/7/2026 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of the note frontmatter. HedgeDoc parsed frontmatter with js-yaml.load (js-yaml v3) via @hedgedoc/meta-marked, which resolved YAML anchor… | |
| Analizada | Alta (7.5) | 0.64% | — | Nodeca Js-yaml | 8/7/2026 | 10/7/2026 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses omapTag.addItem() to perform a linear duplicate-key scan on every insertion, causing O(n^2) CPU consumption when yaml.load() parses a crafted ordered-map document. This… | |
| Analizada | Alta (7.5) | 0.58% | — | Nodeca Js-yaml | 8/7/2026 | 13/7/2026 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and… | |
| Analizada | Alta (7.5) | 0.64% | — | Nodeca Js-yaml | 8/7/2026 | 13/7/2026 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in version 5.2.0. | |
| Analizada | Media (5.3) | 0.41% | — | Nodeca Js-yaml | 22/6/2026 | 9/7/2026 | js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a… | |
| Aplazada | Alta (7.3) | 0.42% | — | Yaml Syck Yaml-syckAI | 12/5/2026 | 17/6/2026 | YAML::Syck versions before 1.38 for Perl has an out-of-bounds read. The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a colon-separated value (e.g., the 1 in 1:30:45), the inner while loop can decrement… | |
| Analizada | Media (4.3) | 0.53% | — | Eemeli Yaml | 26/3/2026 | 17/6/2026 | `yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a depth bound. An… | |
| Modificada | Crítica (9.1) | 0.60% | — | Toddr Yaml\ | 16/3/2026 | 15/7/2026 | YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok… | |
| Analizada | Media (5.3) | 0.41% | — | Nodeca Js-yaml | 13/11/2025 | 17/6/2026 | js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1… | |
| Analizada | Media (6.5) | 0.25% | — | Toddr Yaml\ | 16/10/2025 | 17/6/2026 | YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a hash of all keys and… | |
| Aplazada | Crítica (9.8) | 2.5% | — | Ms-swiftAIPyyamlAI | 1/8/2025 | 17/6/2026 | A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.load() from the PyYAML library (versions = 5.3.1). If an attacker can control the content of the YAML configuration file passed to the --run_config parameter, arbitrary code… | |
| Analizada | Crítica (9.1) | 0.46% | — | Ingydotnet Yaml-libyaml | 1/6/2025 | 17/6/2026 | YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified | |
| Modificada | Alta (7.8) | 0.45% | — | Esotericsoftware Yamlbeans | 25/8/2023 | 17/6/2026 | An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed. | |
| Modificada | Media (5.5) | 0.36% | — | Esotericsoftware Yamlbeans | 25/8/2023 | 17/6/2026 | An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans YamlReader. By exploiting the Anchor feature in YAML, it is possible to generate a small YAML document that, when read, is expanded to a large size, causing CPU and… |