← Vulnerability feed

Vulnerability record · CVE-2022-1471 · published 1 December 2022

CVE-2022-1471: SnakeYaml Constructor deserialization allows remote code execution

Snakeyaml Project · Snakeyaml

SnakeYaml's Constructor() class does not restrict the types it can instantiate during deserialization, so parsing attacker-supplied YAML can lead to remote code execution. The flaw is a deserialization of untrusted data issue (CWE-502) with a critical CVSS 3.1 score of 9.8. Any application that parses untrusted YAML with the default constructor is exposed.

9.8 CVSS 3.1 Critical EPSS 100% · top 0.1% CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, full code execution impact, and very high EPSS despite not being in KEV.

What it is

SnakeYaml's Constructor() class does not restrict the types it can instantiate during deserialization, so parsing attacker-supplied YAML can lead to remote code execution. The flaw is a deserialization of untrusted data issue (CWE-502) with a critical CVSS 3.1 score of 9.8. Any application that parses untrusted YAML with the default constructor is exposed.

Impact

An attacker who controls the YAML content can instantiate arbitrary classes and achieve remote code execution, gaining full control of the affected process. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS vector; the attacker only needs to get malicious YAML into a SnakeYaml parse path. The description does not enumerate specific affected products or entry points beyond SnakeYaml itself.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.99569 probability, 0.99946 percentile) and multiple references carry an Exploit tag, including the Google security-research advisory and marshalsec. Public exploit material exists, though the record does not state whether exploitation has been observed in the wild.

What to do

  • Upgrade SnakeYaml to version 2.0 or later, as the description recommends.
  • Where upgrade is not immediately possible, use SnakeYaml's SafeConstructor when parsing untrusted content to restrict which types can be deserialized.
  • Do not parse YAML from untrusted or unauthenticated sources with the default Constructor.
  • Inventory applications and dependencies that embed SnakeYaml, including transitive uses, and track them for patching.
  • Apply vendor advisories for products that bundle SnakeYaml, such as the referenced Atlassian and NetApp notices.

Detection

  • Monitor application and server logs for deserialization errors or unexpected class instantiation during YAML parsing.
  • Alert on outbound network connections or process execution spawned by services that parse YAML, which may indicate post-exploitation.
  • Search code and dependency manifests for SnakeYaml usage with the default Constructor rather than SafeConstructor.
  • Watch for YAML payloads containing Java type tags or class references in request bodies reaching YAML-parsing endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html
http://www.openwall.com/lists/oss-security/2023/11/19/1
https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479 Issue TrackingThird Party Advisory
https://confluence.atlassian.com/security/cve-2022-1471-snakeyaml-library-rce-vulnerability-in-multiple-products-1296171
https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2 ExploitThird Party Advisory
https://github.com/mbechler/marshalsec ExploitThird Party Advisory
https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc
https://infosecwriteups.com/%EF%B8%8F-inside-the-160-comment-fight-to-fix-snakeyamls-rce-default-1a20c5ca4d4c
https://security.netapp.com/advisory/ntap-20230818-0015/
https://security.netapp.com/advisory/ntap-20240621-0006/
https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true ExploitThird Party Advisory
http://packetstormsecurity.com/files/175095/PyTorch-Model-Server-Registration-Deserialization-Remote-Code-Execution.html
http://www.openwall.com/lists/oss-security/2023/11/19/1
https://bitbucket.org/snakeyaml/snakeyaml/issues/561/cve-2022-1471-vulnerability-in#comment-64581479 Issue TrackingThird Party Advisory
https://github.com/google/security-research/security/advisories/GHSA-mjmj-j48q-9wg2 ExploitThird Party Advisory
https://github.com/mbechler/marshalsec ExploitThird Party Advisory
https://groups.google.com/g/kubernetes-security-announce/c/mwrakFaEdnc
https://security.netapp.com/advisory/ntap-20230818-0015/
https://security.netapp.com/advisory/ntap-20240621-0006/
https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true ExploitThird Party Advisory

Track CVE-2022-1471 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-25857Snakeyaml project snakeyaml vulnerabilityThe package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collection…EPSS 2.7%7.5CVE-2017-18640Snakeyaml project snakeyaml vulnerabilityThe Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.EPSS 27%6.5CVE-2022-41854Snakeyaml project snakeyaml stack-based buffer overflow vulnerabilityThose using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied i…EPSS 1.5%6.5CVE-2022-38749Snakeyaml project snakeyaml stack-based buffer overflow vulnerabilityUsing snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …EPSS 2.1%6.5CVE-2022-38751Snakeyaml project snakeyaml stack-based buffer overflow vulnerabilityUsing snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …EPSS 1.9%6.5CVE-2022-38752Snakeyaml project snakeyaml stack-based buffer overflow vulnerabilityUsing snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …EPSS 2.5%5.5CVE-2022-38750Snakeyaml project snakeyaml stack-based buffer overflow vulnerabilityUsing snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …EPSS 1.3%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV

Source: NIST National Vulnerability Database (record CVE-2022-1471), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.