SnakeYAML < 1.26 is vulnerable to a [Billion Laughs attack](https://en.wikipedia.org/wiki/Billion_laughs_attack) (denial of service). The issue has been tracked in [asomov/snakeyaml#377] and been published in [CVE-2017-18640]. References: * https://cwe.mitre.org/data/definitions/776.html * https://nvd.nist.gov/vuln/detail/CVE-2017-18640 * https://bitbucket.org/asomov/snakeyaml/issues/377 * dropwizard/dropwizard#3223 [asomov/snakeyaml#377]: https://bitbucket.org/asomov/snakeyaml/issues/377/allow-configuration-for-preventing-billion [CVE-2017-18640]: https://nvd.nist.gov/vuln/detail/CVE-2017-18640