๐Ÿ” CVE Alert

CVE-2017-20285

UNKNOWN 0.0

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.

CWE CWE-502 CWE-470
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new unknown vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ingydotnet/yaml-pm/issues/176 github.com: https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch github.com: https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch metacpan.org: https://metacpan.org/release/TINITA/YAML-1.30/changes