perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document
cve CVE-2017-20285 3 sources, 3 claims · Watch
Red Hat writes:
perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document the claim
perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss | Red Hat | 7.4receipt
What the source handed over{
"CVE": "CVE-2017-20285",
"CWE": "CWE-502",
"advisories": [],
"affected_packages": [],
"bugzilla": "2545820",
"bugzilla_description": "perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-05T06:49:17Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2017-20285.json",
"severity": "important"
} | — |
| Cwe cwe not compared | GitHub advisories | CWE-470receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2017-20285",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-470",
"name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')"
}
],
"description": "YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.\n\nA perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.\n\nWhat DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.",
"ghsa_id": "GHSA-c454-fc94-q86x",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-c454-fc94-q86x",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-c454-fc94-q86x"
},
{
"type": "CVE",
"value": "CVE-2017-20285"
}
],
"nvd_published_at": "2026-10-05T07:16:29Z",
"published_at": "2026-10-05T09:31:51Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2017-20285",
"https://github.com/ingydotnet/yaml-pm/issues/176",
"https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch",
"https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch",
"https://metacpan.org/release/TINITA/YAML-1.30/changes",
"https://github.com/advisories/GHSA-c454-fc94-q86x"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of...",
"type": "unreviewed",
"updated_at": "2026-10-05T09:31:56Z",
"url": "https://api.github.com/advisories/GHSA-c454-fc94-q86x",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cwe cwe not compared | Red Hat | CWE-502receipt
What the source handed over{
"CVE": "CVE-2017-20285",
"CWE": "CWE-502",
"advisories": [],
"affected_packages": [],
"bugzilla": "2545820",
"bugzilla_description": "perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-05T06:49:17Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2017-20285.json",
"severity": "important"
} | — |
| Severity severity conflict | GitHub advisories | unknownreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2017-20285",
"cvss": {
"score": null,
"vector_string": null
},
"cvss_severities": {
"cvss_v3": {
"score": 0.0,
"vector_string": null
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-470",
"name": "Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')"
}
],
"description": "YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.\n\nA perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.\n\nWhat DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.",
"ghsa_id": "GHSA-c454-fc94-q86x",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-c454-fc94-q86x",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-c454-fc94-q86x"
},
{
"type": "CVE",
"value": "CVE-2017-20285"
}
],
"nvd_published_at": "2026-10-05T07:16:29Z",
"published_at": "2026-10-05T09:31:51Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2017-20285",
"https://github.com/ingydotnet/yaml-pm/issues/176",
"https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch",
"https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch",
"https://metacpan.org/release/TINITA/YAML-1.30/changes",
"https://github.com/advisories/GHSA-c454-fc94-q86x"
],
"repository_advisory_url": null,
"severity": "unknown",
"source_code_location": "",
"summary": "YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of...",
"type": "unreviewed",
"updated_at": "2026-10-05T09:31:56Z",
"url": "https://api.github.com/advisories/GHSA-c454-fc94-q86x",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Severity severity conflict | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2017-20285",
"CWE": "CWE-502",
"advisories": [],
"affected_packages": [],
"bugzilla": "2545820",
"bugzilla_description": "perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-05T06:49:17Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2017-20285.json",
"severity": "important"
} | high |
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"modules": [
"YAML"
],
"packageName": "YAML",
"packageURL": "pkg:cpan/YAML",
"programFiles": [
"lib/YAML.pm",
"lib/YAML/Loader.pm",
"lib/YAML/Types.pm"
],
"programRoutines": [
{
"name": "YAML::Loader::_parse_explicit"
},
{
"name": "YAML::Type::code::yaml_load"
},
{
"name": "YAML::Type::regexp::yaml_load"
}
],
"repo": "https://github.com/ingydotnet/yaml-pm",
"versions": [
{
"lessThan": "1.30",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.\n\nA perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.\n\nWhat DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names."
}
],
"id": "CVE-2017-20285",
"lastModified": "2026-10-05T07:16:29.017",
"metrics": {},
"published": "2026-10-05T07:16:29.017",
"references": [
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"url": "https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch"
},
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"url": "https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch"
},
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"url": "https://github.com/ingydotnet/yaml-pm/issues/176"
},
{
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"url": "https://metacpan.org/release/TINITA/YAML-1.30/changes"
}
],
"sourceIdentifier": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-470"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| perl-yaml: perl-yaml: Arbitrary destructor method execution via crafted YAML document zetlyn/cve-redhat · 2026-10-05 | cvss 7.4 cwe CWE-502 severity important | source |
| YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes.
A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope.
What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names. zetlyn/cve-nvd · 2026-10-05 | status Received | source |
| YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of... zetlyn/cve-ghsa · 2026-10-05 | cwe CWE-470 severity unknown | source |