Answer in brief
CVE-2017-20285 records a Unknown severity vulnerability in YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. The current sources do not mark it as known exploited. The current feed maps YAML (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps YAML (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| YAMLgeneric | >=0 <1.30 | 1.30 |
Published upstream
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 5, 2026
YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.
Quoted source text, attributed separately from HOL analysis.