AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-20477

CRITICAL · CVSS 9.8 EPSS 5.16% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-02-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-20477
Severity
CRITICAL
CVSS
9.8
EPSS
5.16%

Original NVD Description

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

Related CVEs

Other vulnerabilities affecting the same vendor(s)