Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-14343

34
FAUCET Score

CVE-2020-14343 is a critical arbitrary code execution vulnerability in the PyYAML library, affecting versions prior to 5.4, including Oracle products utilizing it. This flaw allows an unauthenticated attacker to execute arbitrary code by crafting malicious YAML files processed via the full_load method or FullLoader. With a CVSS score of 9.8 (Critical), it presents a high risk due to its network-based attack vector and no user interaction requirement, leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its high EPSS and FAUCET risk scores indicate significant exploitability potential, and it has received some community and media attention, including a mention in a Microsoft Patch Tuesday article.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.1, < 5.4CPE matchmatch criteria
cpe:2.3:a:pyyaml:pyyaml:*:*:*:*:*:*:*:*
1.10.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*
22.1.0CPE matchmatch criteria
cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
5.98%
Probability of exploitation in next 30 days
EPSS Percentile
92.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0598 is in the 87th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: cbl2 PyYAML 5.4.1-1 on CBL Mariner 2.0Fixed in: 5.4.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.4.1-1
microsoftpatch availablevia msrc
Product: 19186-16823Fixed in: 5.4.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.4.1-1
oraclepatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: PyYAMLFixed in: 5.4
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.10 for RHEL 7Fixed in: python-pyyaml-0:5.4.1-1.el7pc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38-devel:3.8-8040020210420090415.6dfe838a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38:3.8-8040020210420090415.6dfe838a
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-python38-PyYAML

Vendor Advisories (4)

microsoft2023-Nov/CVE-2020-14343

CVE-2020-14343

Nov 14, 2023
pipGHSA-8q59-q68h-6hv4critical

Improper Input Validation in PyYAML

Mar 25, 2021
microsoft2021-Feb/CVE-2020-14343Critical

A vulnerability was discovered in the PyYAML library in versions before 5.4 where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. This flaw allows an attacker to execute arbitrary code on the system by abusing the python/object/new constructor. This flaw is due to an incomplete fix for CVE-2020-1747.

Feb 9, 2021
redhatCVE-2020-14343Moderate

PyYAML: incomplete fix for CVE-2020-1747

Jul 22, 2020

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
github.com / SeldonIO/seldon-core/issues/2252
github.com / yaml/pyyaml/issues/420
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory