VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 131 of 166
  • CVE-2023-7018HigDec 20, 2023
    risk 0.44cvss 7.8epss 0.01

    Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

  • CVE-2023-36777MedSep 12, 2023
    risk 0.44cvss 5.7epss 0.52

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2023-21209MedJun 28, 2023
    risk 0.44cvss 6.7epss 0.00

    In multiple functions of sta_iface.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-25647HigMay 1, 2022
    risk 0.44cvss 7.7epss 0.12

    The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

  • CVE-2021-4118HigDec 23, 2021
    risk 0.44cvss 7.8epss 0.01

    pytorch-lightning is vulnerable to Deserialization of Untrusted Data

  • CVE-2021-25738MedOct 11, 2021
    risk 0.44cvss 6.7epss 0.00

    Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

  • CVE-2021-3040MedJun 10, 2021
    risk 0.44cvss 6.7epss 0.01

    An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.

  • CVE-2021-3035MedApr 20, 2021
    risk 0.44cvss 6.7epss 0.01

    An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.

  • CVE-2020-24164HigSep 11, 2020
    risk 0.44cvss 7.8epss 0.01

    A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java…

  • CVE-2013-7489MedJun 26, 2020
    risk 0.44cvss 6.8epss 0.01

    The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.

  • CVE-2019-12086HigMay 17, 2019
    risk 0.44cvss 7.5epss 0.22

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the…

  • CVE-2018-1000167HigApr 18, 2018
    risk 0.44cvss 7.8epss 0.04

    OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can…

  • CVE-2018-1000074HigMar 13, 2018
    risk 0.44cvss 7.8epss 0.03

    RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can…

  • CVE-2026-62997HigSep 16, 2026
    risk 0.43cvss —epss 0.00

    Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-supplied load_args are silently dropped. On…

  • CVE-2026-45794HigSep 15, 2026
    risk 0.43cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, treats top-level blob keys as…

  • CVE-2026-11363MedSep 9, 2026
    risk 0.43cvss 6.6epss 0.01

    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for authenticated attackers, with…

  • CVE-2026-76547MedAug 29, 2026
    risk 0.43cvss 6.6epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is…

  • CVE-2026-59275MedAug 27, 2026
    risk 0.43cvss 6.6epss 0.00

    A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18…

  • CVE-2026-56095HigAug 25, 2026
    risk 0.43cvss —epss 0.00

    The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If…

  • CVE-2026-10035MedAug 16, 2026
    risk 0.43cvss 6.6epss 0.00

    The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of untrusted input in the wvrbbp_set_to_serialized_values() function (reached through the wvrbbp_save_restore()…