Skip to content

Deserialization

Python pickle / dill on untrusted input

April 25, 2026

PyYAML `yaml.load` without a safe Loader

April 25, 2026

Java ObjectInputStream and friends

April 25, 2026

CVE-2017-18342 — PyYAML default `load` resolves arbitrary tags

April 25, 2026