Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-16577 | YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified | 
  Ubuntu USN | 
                USN-7632-1 | YAML-LibYAML vulnerability | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Wed, 02 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Ingydotnet
         Ingydotnet yaml-libyaml  | 
|
| CPEs | cpe:2.3:a:ingydotnet:yaml-libyaml:*:*:*:*:*:perl:*:* | |
| Vendors & Products | 
        
        Ingydotnet
         Ingydotnet yaml-libyaml  | 
Mon, 23 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Redhat
         Redhat enterprise Linux Redhat rhel Eus  | 
|
| CPEs | cpe:/a:redhat:enterprise_linux:8::crb cpe:/a:redhat:enterprise_linux:9::crb cpe:/a:redhat:rhel_eus:9.4::crb  | 
|
| Vendors & Products | 
        
        Redhat
         Redhat enterprise Linux Redhat rhel Eus  | 
Tue, 03 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | |
| Metrics | 
        
        
        threat_severity
         
  | 
    
        
        
        threat_severity
         
  | 
Mon, 02 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 02 Jun 2025 04:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        cvssV3_1
         
  | 
Sun, 01 Jun 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified | |
| Title | YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified | |
| Weaknesses | CWE-552 | |
| References | 
         | 
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2025-06-02T03:22:25.333Z
Reserved: 2025-04-16T09:05:34.360Z
Link: CVE-2025-40908
Updated: 2025-06-02T03:22:20.353Z
Status : Analyzed
Published: 2025-06-01T14:15:21.113
Modified: 2025-07-02T15:43:02.133
Link: CVE-2025-40908
                        OpenCVE Enrichment
                    No data.
 EUVD
 Ubuntu USN