CVE-2017-6920: Drupal

Critical severity, CVSS 9.8. EPSS: 20.5% chance of exploitation in the next 30 days.

Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects safely during certain operations.

Affected products

  • Drupal Drupal: from 8.0.0, before 8.3.4 (fixed in 8.3.4)

Published 2018-08-06. Last modified 2026-06-17.