What is CVE-2026-65636?
CVE-2026-65636 is an improper neutralization of CRLF sequences vulnerability in the ufirstgroup ymlr (Elixir.Ymlr module). It allows attackers to inject arbitrary content into generated YAML documents via document comments by exploiting unescaped line breaks. Affected systems using Ymlr.document!/2 should be updated and comment inputs sanitized immediately.
Azərbaycanca: CVE-2026-65636, ufirstgroup ymlr (Elixir.Ymlr modulu) dokument şərhlərində CRLF ardıcıllıqlarının düzgün zərərsizləşdirilməməsi zəifliyidir. Bu, təcavüzkarlara yaradılan YAML sənədlərinə sətir qırılmaları vasitəsilə ixtiyari məzmun daxil etməyə imkan verir. Təsirə məruz qalan funksiyadan istifadə edən sistemlər dərhal yenilənməli və şərh girişləri yoxlanılmalıdır.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which function in the ufirstgroup ymlr module is affected by CVE-2026-65636?
The vulnerability specifically affects the Ymlr.document!/2 function.
How can an attacker exploiting CVE-2026-65636 inject content into generated YAML documents?
An attacker can inject arbitrary content via document comments by exploiting unescaped line breaks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.