VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 140 of 167
  • CVE-2022-40151MedSep 16, 2022
    risk 0.42cvss 6.5epss 0.02

    Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

  • CVE-2022-37023MedAug 31, 2022
    risk 0.42cvss 6.5epss 0.02

    Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and follow the…

  • CVE-2022-28948HigMay 19, 2022
    risk 0.42cvss 7.5epss 0.04

    An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

  • CVE-2022-0538HigFeb 9, 2022
    risk 0.42cvss 7.5epss 0.04

    Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

  • CVE-2021-43859HigFeb 1, 2022
    risk 0.42cvss 7.5epss 0.08

    XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service…

  • CVE-2021-22097MedOct 28, 2021
    risk 0.42cvss 6.5epss 0.01

    In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util.Dictionary object…

  • CVE-2021-21351MedMar 23, 2021
    risk 0.42cvss 5.4epss 0.82

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is…

  • CVE-2021-21488MedMar 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deserialize user-controlled data without verification, leading to insecure deserialization which triggers the attacker’s code, therefore impacting Availability.

  • CVE-2020-12469MedApr 29, 2020
    risk 0.42cvss 6.5epss 0.01

    admin/blocks.php in Subrion CMS through 4.2.1 allows PHP Object Injection (with resultant file deletion) via serialized data in the subpages value within a block to blocks/edit.

  • CVE-2019-14466MedDec 31, 2019
    risk 0.42cvss 6.5epss 0.01

    The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize…

  • CVE-2019-11458HigMay 8, 2019
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.

  • CVE-2018-12023HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.09

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access,…

  • CVE-2018-12022HigMar 21, 2019
    risk 0.42cvss 7.5epss 0.07

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an…

  • CVE-2018-16476HigNov 30, 2018
    risk 0.42cvss 7.5epss 0.03

    A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions…

  • CVE-2018-15503HigAug 18, 2018
    risk 0.42cvss 7.5epss 0.02

    The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.

  • CVE-2016-10304MedApr 10, 2017
    risk 0.42cvss 6.5epss 0.02

    The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788.

  • CVE-2026-94093MedSep 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possible to launch the attack remotely. The…

  • CVE-2026-90614MedSep 14, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument…

  • CVE-2026-90490MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the…

  • CVE-2026-67260HigAug 12, 2026
    risk 0.41cvss 7.3epss 0.01

    Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task…