VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 128 of 156
  • CVE-2026-12787MedJun 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the argument jdbcUrl results in deserialization.…

  • CVE-2026-45360HigJun 1, 2026
    risk 0.41cvss 7.3epss 0.01

    Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-registry gate. A DAG author whose code…

  • CVE-2026-9497MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the attack remotely. The vendor was contacted…

  • CVE-2026-24142MedMay 20, 2026
    risk 0.41cvss 6.3epss 0.00

    NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-8735MedMay 17, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit…

  • CVE-2026-7712MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may…

  • CVE-2026-5659MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/datrie.pyx of the component trie File Handler. The manipulation results in deserialization. The attack can be launched remotely.…

  • CVE-2026-0677MedMar 20, 2026
    risk 0.41cvss 6.3epss 0.00

    Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1.

  • CVE-2025-13913MedMar 12, 2026
    risk 0.41cvss 6.3epss 0.00

    A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.

  • CVE-2026-3967MedMar 12, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process…

  • CVE-2026-1691MedJan 30, 2026
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component SnakeYAML. Such manipulation leads to deserialization. The attack may be launched…

  • CVE-2025-15453MedJan 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in milvus up to 2.6.7. This vulnerability affects the function expr.Exec of the file pkg/util/expr/expr.go of the component HTTP Endpoint. The manipulation of the argument code leads to deserialization. Remote exploitation of the attack…

  • CVE-2025-15375MedDec 31, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be…

  • CVE-2025-15246MedDec 30, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of the component API. This manipulation of the argument argsStr causes deserialization. Remote exploitation of the attack is…

  • CVE-2025-9191MedNov 26, 2025
    risk 0.41cvss 6.3epss 0.00

    The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via deserialization of untrusted input in saved-search-item.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject…

  • CVE-2025-64439HigNov 7, 2025
    risk 0.41cvss epss 0.01

    LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 2.1.2 and below, the JsonPlusSerializer (used as the default serialization protocol for all checkpointing) contains a Remote Code…

  • CVE-2025-12305MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJobController.java of the component Job Handler. The manipulation results in deserialization. The attack can be executed remotely.…

  • CVE-2025-11346MedOct 6, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remotely. Upgrading to version…

  • CVE-2025-11273MedOct 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oauth/provider.ts. The manipulation of the argument URL results in deserialization. The attack can be executed remotely. The exploit…

  • CVE-2025-10975MedSep 25, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects the function experiments.robot.bridge.reasoning_server::run_reasoning_server of the file experiments/robot/bridge/reasoning_server.py of the component ZeroMQ.…