CVE-2017-20285
Received Received - Intake

YAML Deserialization Flaw in Perl Allows Arbitrary Class Destruction

Vulnerability report for CVE-2017-20285, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: CPANSec

Description

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ingydotnet yaml_pm From 1.30 (exc)
ingydotnet yaml_pm From 1.0 (inc) to 1.30 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in YAML.pm for Perl allows untrusted YAML files to trigger the DESTROY method of arbitrary classes when loaded. By default, the module blesses YAML nodes into objects, including Perl code references. If a malicious YAML file contains a reference to a class with a destructive DESTROY method, it could delete files or perform other harmful actions when the object is destroyed.

Detection Guidance

To detect this vulnerability, check if your system uses YAML.pm versions before 1.30. Run: perl -MYAML -e 'print $YAML::VERSION' to see the installed version. If it's below 1.30, the system is vulnerable. Also inspect Perl scripts that load untrusted YAML files for use of the LoadBlessed option.

Impact Analysis

If you process untrusted YAML files in a Perl application using YAML.pm before version 1.30, an attacker could craft a YAML file to execute destructive actions like deleting directories or files when the object is destroyed. This could lead to data loss or system compromise if the DESTROY method of a class like File::Temp::Dir is triggered.

Compliance Impact

This vulnerability could lead to unauthorized data deletion or modification, violating integrity and availability requirements in GDPR and HIPAA. If exploited, it may result in data breaches or loss of protected health information, potentially leading to regulatory penalties or legal consequences.

Mitigation Strategies

Upgrade YAML.pm to version 1.30 or later. If upgrading isn't possible, set $YAML::LoadBlessed = 0 before loading untrusted YAML data. Avoid using YAML tags like !!perl/code that could trigger object creation. Review scripts for any reliance on automatic object blessing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2017-20285. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart