CVE-2020-1747Patch(fedoraproject / communications_cloud_native_core_network_function_cloud_native_environment)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fedoraproject communications_cloud_native_core_network_function_cloud_native_environment systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • communications_cloud_native_core_network_function_cloud_native_environment
  • fedora
  • leap
  • pyyaml

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
communications_cloud_native_core_network_function_cloud_native_environmentfedoraleappyyaml

6 versions affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-16: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-16: 103-16
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Patch

    A critical RCE vulnerability (CVE-2020-1747) affects `PyYAML` when `yaml.unsafe_load()` processes untrusted input. Update `PyYAML` to 5.3.1+ and use `http://yaml.safe_load()` for external data. #PyYAML #RCE #infosec https://www.pulsepatch.io/posts/cve-2020-1747-pyyaml-arbitrary-code-execution

    Post summary

    The post highlights CVE-2020-1747, a critical remote code execution flaw in PyYAML’s unsafe_load, and tells users to update to 5.3.1+ and switch to safe_load for protection.

    0000029
    1 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora30--
OSfedoraprojectfedora31--
OSfedoraprojectfedora32--
OSfedoraprojectfedora33--
OSopensuseleap15.1--
Apporaclecommunications_cloud_native_core_network_function_cloud_native_environment22.1.0--
Apppyyamlpyyaml---

Explore more