VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 136 of 167
  • CVE-2021-39140MedAug 23, 2021
    risk 0.43cvss 6.5epss 0.06

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of…

  • CVE-2021-23420HigAug 11, 2021
    risk 0.43cvss 7.7epss 0.03

    This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.

  • CVE-2021-21349MedMar 23, 2021
    risk 0.43cvss 6.1epss 0.47

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input…

  • CVE-2021-21345MedMar 23, 2021
    risk 0.43cvss 5.8epss 0.72

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user…

  • CVE-2021-23338MedFeb 15, 2021
    risk 0.43cvss 6.6epss 0.04

    This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

  • CVE-2020-10740MedJun 22, 2020
    risk 0.43cvss 6.6epss 0.02

    A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.

  • CVE-2020-4043HigJun 10, 2020
    risk 0.43cvss 7.7epss 0.03

    phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be…

  • CVE-2020-9484HigMay 20, 2020
    risk 0.43cvss 7.0epss 0.56

    When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore;…

  • CVE-2019-14439HigJul 30, 2019
    risk 0.43cvss 7.5epss 0.11

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.

  • CVE-2026-100846HigSep 27, 2026
    risk 0.42cvss 7.6epss 0.00

    MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application…

  • CVE-2026-93872HigSep 18, 2026
    risk 0.42cvss 7.5epss 0.01

    Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution…

  • CVE-2026-11711MedSep 18, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

  • CVE-2026-57822MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.01

    When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that…

  • CVE-2024-58381HigSep 9, 2026
    risk 0.42cvss 7.5epss 0.00

    PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset…

  • CVE-2026-61686HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can…

  • CVE-2026-82259HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating…

  • CVE-2026-63516MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-62912MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.02

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

  • CVE-2026-71559HigAug 7, 2026
    risk 0.42cvss 7.5epss 0.01

    Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0…

  • CVE-2026-57859HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The…