benjaminfleischer.com
YAML and security in Ruby
If the Ruby YAML implementation allocates and initializs the Ruby objects upon deserialization Since symbols in Ruby aren’t garbage collected, a hash can be crafted to crash the stack
The online whiteboard of Kristofer Palmvik