Vulnerability record · CVE-2022-1471 · published 1 December 2022
CVE-2022-1471: SnakeYaml Constructor deserialization allows remote code execution
Snakeyaml Project · Snakeyaml
SnakeYaml's Constructor() class does not restrict the types it can instantiate during deserialization, so parsing attacker-supplied YAML can lead to remote code execution. The flaw is a deserialization of untrusted data issue (CWE-502) with a critical CVSS 3.1 score of 9.8. Any application that parses untrusted YAML with the default constructor is exposed.
Description
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, full code execution impact, and very high EPSS despite not being in KEV.
What it is
SnakeYaml's Constructor() class does not restrict the types it can instantiate during deserialization, so parsing attacker-supplied YAML can lead to remote code execution. The flaw is a deserialization of untrusted data issue (CWE-502) with a critical CVSS 3.1 score of 9.8. Any application that parses untrusted YAML with the default constructor is exposed.
Impact
An attacker who controls the YAML content can instantiate arbitrary classes and achieve remote code execution, gaining full control of the affected process. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) required, per the CVSS vector; the attacker only needs to get malicious YAML into a SnakeYaml parse path. The description does not enumerate specific affected products or entry points beyond SnakeYaml itself.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.99569 probability, 0.99946 percentile) and multiple references carry an Exploit tag, including the Google security-research advisory and marshalsec. Public exploit material exists, though the record does not state whether exploitation has been observed in the wild.
What to do
- Upgrade SnakeYaml to version 2.0 or later, as the description recommends.
- Where upgrade is not immediately possible, use SnakeYaml's SafeConstructor when parsing untrusted content to restrict which types can be deserialized.
- Do not parse YAML from untrusted or unauthenticated sources with the default Constructor.
- Inventory applications and dependencies that embed SnakeYaml, including transitive uses, and track them for patching.
- Apply vendor advisories for products that bundle SnakeYaml, such as the referenced Atlassian and NetApp notices.
Detection
- Monitor application and server logs for deserialization errors or unexpected class instantiation during YAML parsing.
- Alert on outbound network connections or process execution spawned by services that parse YAML, which may indicate post-exploitation.
- Search code and dependency manifests for SnakeYaml usage with the default Constructor rather than SafeConstructor.
- Watch for YAML payloads containing Java type tags or class references in request bodies reaching YAML-parsing endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-1471 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1471), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.