CVE-2019-25777: YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution
Stig Palmquist 05 Oct 2026 06:51 UTC
========================================================================
CVE-2019-25777 CPAN Security Group
========================================================================
CVE ID: CVE-2019-25777
Distribution: YAML
Versions: before 1.27_001
MetaCPAN: https://metacpan.org/dist/YAML
VCS Repo: https://github.com/ingydotnet/yaml-pm
YAML versions before 1.27_001 for Perl allow a loaded perl/glob
document to replace any package variable, which can lead to arbitrary
code execution
Description
-----------
YAML versions before 1.27_001 for Perl allow a loaded perl/glob
document to replace any package variable, which can lead to arbitrary
code execution.
A perl/glob document names a package and a symbol, and supplies the
value assigned to it. Nothing restricts the name, so the target can be
@INC or YAML's own load options.
A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns
on code loading, which is off by default, for every later Load() in the
process. A perl/code document is then passed to a string eval, so an
attacker who supplies two documents to separate Load() calls in one
process can execute arbitrary Perl code.
Problem types
-------------
- CWE-914 Improper Control of Dynamically-Identified Variables
- CWE-502 Deserialization of Untrusted Data
Workarounds
-----------
For deployments that cannot upgrade to YAML 1.28, set
$YAML::LoadBlessed = 0 before loading untrusted input. The option
exists from YAML 1.25 and gates glob loading too.
Solutions
---------
Upgrade to YAML 1.28 or later.
References
----------
https://github.com/ingydotnet/yaml-pm/issues/212
https://github.com/ingydotnet/yaml-pm/commit/bace96b5e6661d521c7c515c94a09e081c911fce.patch
https://metacpan.org/release/TINITA/YAML-1.28/changes
Timeline
--------
- 2019-04-27: Issue reported.
- 2019-04-27: Version 1.27_001 released with fix.
- 2019-04-28: Version 1.28 released with fix.
- 2022-06-27: Issue added as CPANSA-YAML-2019-01 in the CPAN::Audit
database.
- 2026-09-21: CVE number reserved.