CVE-2017-20285

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

YAML versions before 1.30 for Perl allow a loaded document to trigger the DESTROY method of arbitrary classes. A perl/hash:Class tag blesses a hash into the class it names. The document supplies the object's fields, and Perl calls DESTROY when it goes out of scope. What DESTROY does depends on the classes the process has loaded. With File::Temp::Dir from core Perl, it can delete a directory tree the document names.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-06: 210-06
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2017-20285 Vendor → Unknown Severity → Critical — CVSS 9.1 Product → Unknown Date → 2026-10-05 A critical vulnerability (Unsafe Reflection) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000050
    449 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - YAML for Perl Unsafe Deserialization via Bless/DESTROY Gadget (CVE-2017-20285) http://YAML.pm < 1.30 deserializes crafted YAML that blesses a hash into an arbitrary class; when the object is freed, Perl invokes the class DESTROY method. If a gadget class is loaded (e.g., File::Temp::Dir), attackers can trigger destructive actions like recursive deletion. 👉Affected: YAML (Perl) < 1.30 | Upgrade to 1.30

    0000063
    311 followersView on X

Explore more