{"id":"CVE-2019-10135","details":"A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the yaml.load() function allowed the user to load any suspicious object for code execution via the parsing of malicious YAML files.","modified":"2026-07-08T20:15:35.194310Z","published":"2019-07-11T19:15:12.563Z","references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10135"},{"type":"FIX","url":"https://github.com/containerbuildsystem/osbs-client/pull/865"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/containerbuildsystem/osbs-client","events":[{"introduced":"bd0523ee69a40134053ff4264dcd7273ae282281"},{"fixed":"b265a29a8d115f9ca77a55f6c89212d6d1f6f300"}],"database_specific":{"cpe":"cpe:2.3:a:osbs-client_project:osbs-client:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.46"},{"fixed":"0.56.1"}],"source":"CPE_RANGE"}}],"versions":["0.56","0.55","0.54","0.53","0.52","0.51","0.48","0.46"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10135.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}