CVE-2017-20285
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
| CWE | CWE-502 CWE-470 |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new unknown vulnerabilities are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
References
github.com: https://github.com/ingydotnet/yaml-pm/issues/176 github.com: https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch github.com: https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch metacpan.org: https://metacpan.org/release/TINITA/YAML-1.30/changes