CVE-2019-25777
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution
CVSS v3
7.3
HIGH
EPSS Score
0.2 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options. A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is
Technical details
- CVSS v3 Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Published
- 2026-10-05
- Last Modified
- 2026-10-06
Frequently asked questions
What is CVE-2019-25777?
YAML versions before 1.27_001 for Perl allow a loaded perl/glob document to replace any package variable, which can lead to arbitrary code execution. A perl/glob document names a package and a symbol, and supplies the value assigned to it. Nothing restricts the name, so the target can be @INC or YAML's own load options. A perl/glob document that sets $YAML::LoadCode or $YAML::UseCode turns on code loading, which is off by default, for every later Load() in the process. A perl/code document is
Is CVE-2019-25777 actively exploited?
Active exploitation of CVE-2019-25777 has not been confirmed. Its EPSS score was 0.2% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2019-25777?
CVE-2019-25777 has a CVSS v3 base score of 7.3 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L.
Is CVE-2019-25777 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2019 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).