<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:53:19 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:9329 — Important: perl-YAML-LibYAML security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:9329</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl-YAML-LibYAML&lt;/p&gt;
&lt;p&gt;Kirill Siminov&amp;#39;s &amp;#34;libyaml&amp;#34; is arguably the best YAML implementation. The C library is written precisely to the YAML 1.1 specification. It was originally bound to Python and was later bound to Ruby.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* yaml-libyaml: LibYAML Perl File Modification Vulnerability (CVE-2025-40908)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl-YAML-LibYAML&lt;/p&gt;
&lt;p&gt;Kirill Siminov&amp;#39;s &amp;#34;libyaml&amp;#34; is arguably the best YAML implementation. The C library is written precisely to the YAML 1.1 specification. It was originally bound to Python and was later bound to Ruby.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* yaml-libyaml: LibYAML Perl File Modification Vulnerability (CVE-2025-40908)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:9329</guid>
    </item>
    <item>
      <title>bdu:2025-08363</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08363</link>
      <description>bdu:2025-08363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08363</guid>
    </item>
    <item>
      <title>EUVD-2026-242291</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-242291</link>
      <description>EUVD-2026-242291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-242291</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40908</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40908</link>
      <description>&lt;p&gt;YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40908</guid>
    </item>
    <item>
      <title>GHSA-jh9m-3m95-c6hp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jh9m-3m95-c6hp</link>
      <description>&lt;p&gt;YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jh9m-3m95-c6hp</guid>
    </item>
    <item>
      <title>OESA-2025-1591 — perl-YAML-LibYAML security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1591</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: perl-YAML-LibYAML, openEuler:24.03-LTS: perl-YAML-LibYAML, openEuler:24.03-LTS-SP1: perl-YAML-LibYAML, openEuler:20.03-LTS-SP4: perl-YAML-LibYAML, openEuler:22.03-LTS-SP3: perl-YAML-LibYAML&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in TINITA YAML-LibYAML up to 0.902.x on Perl. It has been classified as problematic.CWE is classifying the issue as CWE-552. The product makes files or directories accessible to unauthorized actors, even though they should not be.This is going to have an impact on confidentiality.Upgrading to version 0.903.0 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.(CVE-2025-40908)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: perl-YAML-LibYAML, openEuler:24.03-LTS: perl-YAML-LibYAML, openEuler:24.03-LTS-SP1: perl-YAML-LibYAML, openEuler:20.03-LTS-SP4: perl-YAML-LibYAML, openEuler:22.03-LTS-SP3: perl-YAML-LibYAML&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability was found in TINITA YAML-LibYAML up to 0.902.x on Perl. It has been classified as problematic.CWE is classifying the issue as CWE-552. The product makes files or directories accessible to unauthorized actors, even though they should not be.This is going to have an impact on confidentiality.Upgrading to version 0.903.0 eliminates this vulnerability. Applying a patch is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.(CVE-2025-40908)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1591</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15261-1 — perl-YAML-LibYAML-0.904.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15261-1</link>
      <description>&lt;p&gt;perl-YAML-LibYAML-0.904.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-YAML-LibYAML-0.904.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15261-1</guid>
    </item>
    <item>
      <title>RHSA-2025:9338 — Red Hat Security Advisory: perl-YAML-LibYAML security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:9338</link>
      <description>&lt;p&gt;yaml-libyaml: LibYAML Perl File Modification Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;yaml-libyaml: LibYAML Perl File Modification Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:9338</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:01885-1 — Security update for perl-YAML-LibYAML</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:01885-1</link>
      <description>&lt;p&gt;Security update for perl-YAML-LibYAML&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for perl-YAML-LibYAML&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:01885-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40908</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40908</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libyaml-libyaml-perl, Ubuntu:18.04:LTS: libyaml-libyaml-perl, Ubuntu:20.04:LTS: libyaml-libyaml-perl, Ubuntu:22.04:LTS: libyaml-libyaml-perl, Ubuntu:24.04:LTS: libyaml-libyaml-perl&lt;/p&gt;
&lt;p&gt;YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: libyaml-libyaml-perl, Ubuntu:18.04:LTS: libyaml-libyaml-perl, Ubuntu:20.04:LTS: libyaml-libyaml-perl, Ubuntu:22.04:LTS: libyaml-libyaml-perl, Ubuntu:24.04:LTS: libyaml-libyaml-perl&lt;/p&gt;
&lt;p&gt;YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40908</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1370 — Red Hat Enterprise Linux (yaml-libyam): Schwachstelle ermöglicht Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1370</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1370</guid>
    </item>
  </channel>
</rss>
