CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 136 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39140 | Med | 0.43 | 6.5 | 0.06 | Aug 23, 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of… | ||
| CVE-2021-23420 | Hig | 0.43 | 7.7 | 0.03 | Aug 11, 2021 | This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation. | ||
| CVE-2021-21349 | Med | 0.43 | 6.1 | 0.47 | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input… | ||
| CVE-2021-21345 | Med | 0.43 | 5.8 | 0.72 | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user… | ||
| CVE-2021-23338 | Med | 0.43 | 6.6 | 0.04 | Feb 15, 2021 | This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function. | ||
| CVE-2020-10740 | Med | 0.43 | 6.6 | 0.02 | Jun 22, 2020 | A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly. | ||
| CVE-2020-4043 | Hig | 0.43 | 7.7 | 0.03 | Jun 10, 2020 | phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be… | ||
| CVE-2020-9484 | Hig | 0.43 | 7.0 | 0.56 | May 20, 2020 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore;… | ||
| CVE-2019-14439 | Hig | 0.43 | 7.5 | 0.11 | Jul 30, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath. | ||
| CVE-2026-100846 | Hig | 0.42 | 7.6 | 0.00 | Sep 27, 2026 | MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application… | ||
| CVE-2026-93872 | Hig | 0.42 | 7.5 | 0.01 | Sep 18, 2026 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution… | ||
| CVE-2026-11711 | Med | 0.42 | 6.5 | 0.00 | Sep 18, 2026 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component. | ||
| CVE-2026-57822 | Med | 0.42 | 6.5 | 0.01 | Sep 10, 2026 | When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that… | ||
| CVE-2024-58381 | Hig | 0.42 | 7.5 | 0.00 | Sep 9, 2026 | PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset… | ||
| CVE-2026-61686 | Hig | 0.42 | 7.5 | 0.00 | Sep 4, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can… | ||
| CVE-2026-82259 | Hig | 0.42 | 7.5 | 0.01 | Aug 28, 2026 | SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating… | ||
| CVE-2026-63516 | Med | 0.42 | 6.5 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-62912 | Med | 0.42 | 6.5 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-71559 | Hig | 0.42 | 7.5 | 0.01 | Aug 7, 2026 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0… | ||
| CVE-2026-57859 | Hig | 0.42 | 7.5 | 0.01 | Jul 30, 2026 | e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The… |
- risk 0.43cvss 6.5epss 0.06
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of…
- risk 0.43cvss 7.7epss 0.03
This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.
- risk 0.43cvss 6.1epss 0.47
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input…
- risk 0.43cvss 5.8epss 0.72
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user…
- risk 0.43cvss 6.6epss 0.04
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
- risk 0.43cvss 6.6epss 0.02
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.
- risk 0.43cvss 7.7epss 0.03
phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be…
- risk 0.43cvss 7.0epss 0.56
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore;…
- risk 0.43cvss 7.5epss 0.11
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
- risk 0.42cvss 7.6epss 0.00
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application…
- risk 0.42cvss 7.5epss 0.01
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution…
- risk 0.42cvss 6.5epss 0.00
IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.
- risk 0.42cvss 6.5epss 0.01
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that…
- risk 0.42cvss 7.5epss 0.00
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset…
- risk 0.42cvss 7.5epss 0.00
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can…
- risk 0.42cvss 7.5epss 0.01
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating…
- risk 0.42cvss 6.5epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.02
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- risk 0.42cvss 7.5epss 0.01
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0…
- risk 0.42cvss 7.5epss 0.01
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The…