CVE-2026-75432

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

  • Published Sep 22, 2026
  • CVSS 5.1 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

CVE-2026-75432 at the National Vulnerability Database