CVE-2017-18640 describes an entity expansion vulnerability in the Alias feature of SnakeYAML versions prior to 1.26, affecting products like fedoraproject, oracle, and quarkus. This high-severity vulnerability (CVSS 7.5) can lead to a denial of service (A:H) through an unauthenticated network attack (AV:N/AC:L/PR:N/UI:N/S:U), similar to CVE-2003-1564. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, its FAUCET Risk Score of 60/100 indicates a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.26CPE matchmatch criteria | cpe:2.3:a:snakeyaml_project:snakeyaml:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
<= 1.3.4CPE matchmatch criteria | cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:* | ||
8.56CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_pt_peopletools:8.56:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SnakeYAML Entity Expansion during load operation
Jun 4, 2021snakeyaml: Billion laughs attack via alias feature
Dec 12, 2019The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
Dec 10, 2019