CVE-2017-18640: High severity Snakeyaml Project Snakeyaml vulnerability
Last updated 28 March 2025
Other sources
The Alias feature in SnakeYAML 1.18 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
Reference: https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion
— Red Hat
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18640?
CVE-2017-18640 has a medium severity due to its potential for entity expansion vulnerabilities.
How do I fix CVE-2017-18640?
To fix CVE-2017-18640, update SnakeYAML to version 1.26 or later.
Which versions of SnakeYAML are affected by CVE-2017-18640?
CVE-2017-18640 affects all versions of SnakeYAML prior to 1.26.
What applications are at risk due to CVE-2017-18640?
Applications using affected versions of SnakeYAML, such as Oracle PeopleSoft and Red Hat Quarkus, are at risk.
Is CVE-2017-18640 related to other vulnerabilities?
Yes, CVE-2017-18640 is related to CVE-2003-1564, sharing similar entity expansion issues.