The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
https://www.oracle.com/security-alerts/cpuApr2021.html
https://security.gentoo.org/glsa/202305-28
https://mvnrepository.com/artifact/org.yaml/snakeyaml/1.25/usages
https://bitbucket.org/snakeyaml/snakeyaml/wiki/Changes
https://bitbucket.org/asomov/snakeyaml/wiki/Billion%20laughs%20attack