PatchSiren cyber security CVE debrief
CVE-2026-75432 jbeder CVE debrief
CVE-2026-75432 is a medium-severity vulnerability in yaml-cpp 0.9.0, affecting the src/scanner.cpp component, specifically in the Scanner::PopIndent() and Scanner::PushIndentTo() functions. This issue allows remote attackers to obtain sensitive information. The vulnerability has been assessed as medium severity with a CVSS score of 5.1. Developers and administrators using yaml-cpp 0.9.0 should assess their exposure and consider updating to a version without this issue. The CVE record was published on 2026-09-22T20:17:05.377Z.
- Vendor
- jbeder
- Product
- yaml-cpp
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-10-03
Who should care
Developers and administrators using yaml-cpp 0.9.0 in their applications should assess their exposure to this vulnerability and consider updating to a version without this issue
Why it matters
CVE-2026-75432 is a medium-severity vulnerability in yaml-cpp 0.9.0 that allows remote attackers to obtain sensitive information. Defenders should assess their exposure and consider updating to a version without this vulnerability.
- Obtain sensitive information via src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components requires verification
- Defenders should verify yaml-cpp 0.9.0 usage and exposure
Technical summary
The yaml-cpp 0.9.0 library has an issue in src/scanner.cpp, specifically in the Scanner::PopIndent() and Scanner::PushIndentTo() components, which allows a remote attacker to obtain sensitive information via these components. This issue has been confirmed by CVE Program and NVD records, indicating that yaml-cpp 0.9.0 is vulnerable to information disclosure. Defenders should assess their exposure and consider updating to a version without this vulnerability.
Defensive priority
Assess yaml-cpp 0.9.0 usage and verify exposure
Recommended defensive actions
- Assess yaml-cpp 0.9.0 usage in your environment
- Verify exposure to sensitive information via src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components
- Consider updating yaml-cpp to a version without this vulnerability
Evidence notes
CVE Program and NVD records indicate an issue in yaml-cpp 0.9.0 allowing remote attackers to obtain sensitive information via src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75432 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75432
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75432 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75432
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/jbeder/yaml-cpp/issues/1475
-
Source reference
Unverified legacy reference
URL: https://github.com/jbeder/yaml-cpp/pull/1476
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.