It was found that using yaml.load() API on untrusted input could lead to arbitrary code execution (CVE-2017-18342).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2019-0125.json"