CVE-2017-20285: YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes Stig Palmquist 05 Oct 2026 06:54 UTC

========================================================================
CVE-2017-20285                                       CPAN Security Group
========================================================================

        CVE ID:  CVE-2017-20285

  Distribution:  YAML
      Versions:  before 1.30
      MetaCPAN:  https://metacpan.org/dist/YAML
      VCS Repo:  https://github.com/ingydotnet/yaml-pm

YAML versions before 1.30 for Perl allow a loaded document to trigger
the DESTROY method of arbitrary classes

Description
-----------
YAML versions before 1.30 for Perl allow a loaded document to trigger
the DESTROY method of arbitrary classes.

A perl/hash:Class tag blesses a hash into the class it names. The
document supplies the object's fields, and Perl calls DESTROY when it
goes out of scope.

What DESTROY does depends on the classes the process has loaded. With
File::Temp::Dir from core Perl, it can delete a directory tree the
document names.

Problem types
-------------
- CWE-502 Deserialization of Untrusted Data
- CWE-470 Use of Externally-Controlled Input to Select Classes or Code
  ('Unsafe Reflection')

Workarounds
-----------
For deployments that cannot upgrade to YAML 1.30, set
$YAML::LoadBlessed = 0 before loading untrusted input. The option
exists from YAML 1.25.

Solutions
---------
Upgrade to YAML 1.30 or later.

References
----------
https://github.com/ingydotnet/yaml-pm/issues/176
https://github.com/ingydotnet/yaml-pm/commit/471314bbdcbd62077eea32755929122aa8bd00a3.patch
https://github.com/ingydotnet/yaml-pm/commit/7736f38bd02e4f9f77d5468721e3be3d7b34a8ec.patch
https://metacpan.org/release/TINITA/YAML-1.30/changes

Timeline
--------
- 2017-05-10: Issue reported.
- 2018-05-11: Version 1.25 released with the $YAML::LoadBlessed option.
- 2020-01-27: Version 1.30 released with the option defaulting to off.
- 2022-06-27: Issue added as CPANSA-YAML-2017-01 in the CPAN::Audit
  database.
- 2026-09-21: CVE number reserved.