VYPR

YAML

by Perl Foundation

CVEs (1)

  • CVE-2017-20285Oct 5, 2026
    risk 0.00cvss —epss —

    YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What…