CVE-2019-25777: 
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2019-25777 is an arbitrary code execution vulnerability in the YAML module for Perl (also known as yaml-pm) affecting all versions before 1.27_001. The flaw allows a maliciously crafted perl/glob YAML document to replace arbitrary Perl package variables, which can be leveraged to enable code loading and subsequently execute arbitrary Perl code. The vulnerability was originally reported on April 27, 2019, and formally assigned a CVE and published to the NVD and GitHub Advisory Database in October 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Red Hat Advisory, Github Advisory).

Détails techniques

The root cause is classified as CWE-502 (Deserialization of Untrusted Data) and CWE-914 (Improper Control of Dynamically-Identified Variables). When the YAML module processes a perl/glob document, it assigns a value to a named package variable without any restriction on which variable can be targeted. An attacker can exploit this in two stages across separate Load() calls within the same process: first, supply a perl/glob document that sets $YAML::LoadCode or $YAML::UseCode to a truthy value (enabling code loading, which is off by default); then supply a perl/code document that is passed to Perl's string eval, executing arbitrary code. The fix, committed by Tina Müller on April 27, 2019, gates glob loading behind a check that $YAML::LoadBlessed and load_code are both enabled (GitHub Issue, Patch).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary Perl code with the privileges of the application process that invokes YAML::Load(). This results in full compromise of confidentiality, integrity, and availability of the affected system. Depending on the application context, an attacker could exfiltrate sensitive data, modify application state, install backdoors, or pivot to other systems accessible from the compromised process (Red Hat Advisory, Github Advisory).

Exploitabilité

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The attack requires the ability to supply two separate YAML documents to distinct Load() calls within the same process, which raises the attack complexity to High (reflected in the CVSS score). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the EPSS score is reported as 0.0 (Red Hat Advisory, Github Advisory).

Étapes d’exploitation

  1. Identify target: Locate an application that uses the Perl YAML module (versions before 1.27_001) and accepts untrusted YAML input across multiple Load() calls within the same process.
  2. Craft first payload (glob document): Construct a perl/glob YAML document that targets the $YAML::LoadCode or $YAML::UseCode package variable and sets it to a truthy value, e.g.:
--- !!perl/glob
  package: YAML
  name: LoadCode
  SCALAR: 1
  1. Submit first document: Supply this document to the application so it is processed by a YAML::Load() call, enabling code loading for all subsequent Load() calls in the process.
  2. Craft second payload (code document): Construct a perl/code YAML document containing the arbitrary Perl code to execute, e.g.:
--- !!perl/code
  'system("id > /tmp/pwned");'
  1. Submit second document: Supply this document to a subsequent YAML::Load() call in the same process; the code is passed to string eval and executed with the privileges of the application process (GitHub Issue, Patch).

Indicateurs de compromis

  • Logs: Application logs showing YAML parsing of documents containing !!perl/glob or !!perl/code tags from untrusted input sources.
  • Process: Unexpected child processes spawned by the Perl application process (e.g., sh, bash, curl, wget) following YAML document processing.
  • File System: Unexpected files created by the application process (e.g., output files from system commands, new scripts, or web shells in application directories).
  • Network: Unusual outbound network connections initiated by the Perl application process after processing YAML input, potentially indicating reverse shell or data exfiltration activity.

Atténuation et solutions de contournement

Upgrade the Perl YAML module to version 1.27_001 or later (the fix was included in the YAML-1.28 release on CPAN). If immediate patching is not possible, restrict the application so that untrusted input cannot be passed to YAML::Load(), or implement input validation to reject documents containing !!perl/glob and !!perl/code tags before processing. Ensure that $YAML::LoadCode and $YAML::UseCode remain set to their default values (false/0) and are not modifiable by external input (Github Advisory, Patch).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2019-25777HIGH8.1
  • Linux Debian logoLinux Debian
  • perl-YAML
NonOuiOct 05, 2026
CVE-2017-20285HIGH7.4
  • Linux Debian logoLinux Debian
  • libyaml-perl
NonOuiOct 05, 2026
CVE-2026-94291MEDIUM6.5
  • Linux Debian logoLinux Debian
  • epiphany-browser
NonNonOct 05, 2026
CVE-2026-97873MEDIUM5.3
  • Bouncy Castle logoBouncy Castle
  • bouncycastle
NonOuiOct 03, 2026
CVE-2026-19954NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-whois-raw-perl
NonNonOct 05, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités