CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,104)
page 122 of 156| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36777 | Med | 0.44 | 5.7 | 0.81 | Sep 12, 2023 | Microsoft Exchange Server Information Disclosure Vulnerability | ||
| CVE-2023-21209 | Med | 0.44 | 6.7 | 0.00 | Jun 28, 2023 | In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2022-25647 | Hig | 0.44 | 7.7 | 0.12 | May 1, 2022 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. | ||
| CVE-2021-4118 | Hig | 0.44 | 7.8 | 0.01 | Dec 23, 2021 | pytorch-lightning is vulnerable to Deserialization of Untrusted Data | ||
| CVE-2021-25738 | Med | 0.44 | 6.7 | 0.00 | Oct 11, 2021 | Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. | ||
| CVE-2021-3040 | Med | 0.44 | 6.7 | 0.01 | Jun 10, 2021 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted. | ||
| CVE-2021-3035 | Med | 0.44 | 6.7 | 0.01 | Apr 20, 2021 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted. | ||
| CVE-2020-24164 | Hig | 0.44 | 7.8 | 0.01 | Sep 11, 2020 | A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java… | ||
| CVE-2013-7489 | Med | 0.44 | 6.8 | 0.01 | Jun 26, 2020 | The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution. | ||
| CVE-2019-12086 | Hig | 0.44 | 7.5 | 0.22 | May 17, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the… | ||
| CVE-2018-1000167 | Hig | 0.44 | 7.8 | 0.04 | Apr 18, 2018 | OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can… | ||
| CVE-2018-1000074 | Hig | 0.44 | 7.8 | 0.03 | Mar 13, 2018 | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can… | ||
| CVE-2026-68756 | Med | 0.43 | 6.6 | 0.00 | Aug 12, 2026 | A party with write access to stored session data may affect JFrog Artifactory under specific conditions. | ||
| CVE-2026-12115 | Med | 0.43 | 6.6 | 0.01 | Jun 17, 2026 | The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with… | ||
| CVE-2026-7566 | Med | 0.43 | 6.6 | 0.00 | Jun 6, 2026 | The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and… | ||
| CVE-2026-48919 | Med | 0.43 | 6.6 | 0.00 | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | ||
| CVE-2026-48917 | Med | 0.43 | 6.6 | 0.00 | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. | ||
| CVE-2025-67779 | Hig | 0.43 | 7.5 | 0.20 | Dec 12, 2025 | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads… | ||
| CVE-2025-67535 | Med | 0.43 | 6.6 | 0.00 | Dec 9, 2025 | Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6. | ||
| CVE-2025-54053 | Med | 0.43 | 6.6 | 0.00 | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2. |
- risk 0.44cvss 5.7epss 0.81
Microsoft Exchange Server Information Disclosure Vulnerability
- risk 0.44cvss 6.7epss 0.00
In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.44cvss 7.7epss 0.12
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.
- risk 0.44cvss 7.8epss 0.01
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
- risk 0.44cvss 6.7epss 0.00
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
- risk 0.44cvss 6.7epss 0.01
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.
- risk 0.44cvss 6.7epss 0.01
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.
- risk 0.44cvss 7.8epss 0.01
A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java…
- risk 0.44cvss 6.8epss 0.01
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
- risk 0.44cvss 7.5epss 0.22
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the…
- risk 0.44cvss 7.8epss 0.04
OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can…
- risk 0.44cvss 7.8epss 0.03
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can…
- risk 0.43cvss 6.6epss 0.00
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
- risk 0.43cvss 6.6epss 0.01
The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.13 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…
- risk 0.43cvss 6.6epss 0.00
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, with administrator-level access and…
- risk 0.43cvss 6.6epss 0.00
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
- risk 0.43cvss 6.6epss 0.00
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
- risk 0.43cvss 7.5epss 0.20
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads…
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Flipper Code - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6.
- risk 0.43cvss 6.6epss 0.00
Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue affects Groundhogg: from n/a through <= 4.2.2.