CVE-2026-88359
libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.
- Published Sep 24, 2026
- CVSS 6.5 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available