{"schema_version":"1.7.2","id":"OESA-2026-3238","modified":"2026-08-07T09:17:00Z","published":"2026-08-07T09:17:00Z","upstream":["CVE-2026-63676"],"summary":"perl-YAML security update","details":"The YAML.pm module implements a YAML Loader and Dumper based on the YAML 1.0 specification. http://www.yaml.org/spec/ YAML is a generic data serialization language that is optimized for human readability.It can be used to express the data structures of most modern programming languages. (Including Perl!!!) For information on the YAML syntax, please refer to the YAML specification.\n\nSecurity Fix(es):\n\nThe MPG WordPress plugin prior to 4.1.8 does not sanitize and escape parameters before reflecting them back into the response, allowing an unauthenticated attacker to perform reflected cross-site scripting against a victim who is induced to send a crafted request.(CVE-2026-63676)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP1","name":"perl-YAML","purl":"pkg:rpm/openEuler/perl-YAML&distro=openEuler-24.03-LTS-SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.321-1.oe2403sp1"}]}],"ecosystem_specific":{"noarch":["perl-YAML-1.321-1.oe2403sp1.noarch.rpm","perl-YAML-help-1.321-1.oe2403sp1.noarch.rpm"],"src":["perl-YAML-1.321-1.oe2403sp1.src.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3238"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63676"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"}],"database_specific":{"severity":"Low"}}
