DeserializationPython pickle / dill on untrusted inputApril 25, 2026PyYAML `yaml.load` without a safe LoaderApril 25, 2026Java ObjectInputStream and friendsApril 25, 2026CVE-2017-18342 — PyYAML default `load` resolves arbitrary tagsApril 25, 2026