4 ms·
> Imagine I make a serialisation/deserialisation library which would be vulnerable if you fed it untrusted data No need to imagine, the PyYAML has that situati
by Elucalidavah 2y ago
> Imagine I make a serialisation/deserialisation library which would be vulnerable if you fed it untrusted data
No need to imagine, the PyYAML has that situation. There have been attempts to use the safe deserialization by default, with an attempt to release a new major version (rolled back), and it settled on having a required argument of which mode / loader to use. See: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=PyYAML https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=PyYAML