VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 145 of 156
  • CVE-2026-5507MedApr 9, 2026
    risk 0.19cvss 4.0epss 0.00

    When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the…

  • CVE-2026-50522CriKEVJul 14, 2026
    risk 0.18cvss 9.8epss 0.77

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  • CVE-2024-6525LowJul 5, 2024
    risk 0.18cvss 2.7epss 0.03

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The…

  • CVE-2026-35537LowApr 3, 2026
    risk 0.17cvss 3.7epss 0.00

    An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

  • CVE-2026-24656LowJan 26, 2026
    risk 0.17cvss 3.7epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket…

  • CVE-2022-39379LowNov 2, 2022
    risk 0.17cvss 3.1epss 0.45

    Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially…

  • CVE-2024-47836LowOct 16, 2024
    risk 0.16cvss 3.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.

  • CVE-2024-3366LowApr 6, 2024
    risk 0.16cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has…

  • CVE-2024-22460LowMay 8, 2024
    risk 0.14cvss 2.2epss 0.00

    Dell PowerProtect DM5500 version 5.15.0.0 and prior contains an insecure deserialization Vulnerability. A remote attacker with high privileges could potentially exploit this vulnerability, leading to arbitrary code execution on the vulnerable application.

  • CVE-2023-49297LowDec 5, 2023
    risk 0.14cvss 3.3epss 0.01

    PyDrive2 is a wrapper library of google-api-python-client that simplifies many common Google Drive API V2 tasks. Unsafe YAML deserilization will result in arbitrary code execution. A maliciously crafted YAML file can cause arbitrary code execution if PyDrive2 is run in the same…

  • CVE-2026-58644CriKEVJul 14, 2026
    risk 0.12cvss 9.8epss 0.45

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  • CVE-2025-61677LowOct 3, 2025
    risk 0.09cvss 2.5epss 0.00

    DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and below allow for deseriaization of untrusted data because of the way the DataChain library reads serialized objects from environment variables (such as…

  • CVE-2019-12799HigJun 13, 2019
    risk 0.07cvss 8.8epss 0.55

    In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to…

  • CVE-2021-21242CriJan 15, 2021
    risk 0.06cvss 10.0epss 0.74

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce…

  • CVE-2021-3007CriJan 4, 2021
    risk 0.06cvss 9.8epss 0.75

    Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend…

  • CVE-2021-21243CriJan 15, 2021
    risk 0.04cvss 10.0epss 0.54

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods that deserialize untrusted data from the request body. These endpoints do not enforce any authentication or authorization checks. This issue may lead to…

  • CVE-2007-1701Mar 27, 2007
    risk 0.04cvss epss 0.09

    PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to execute arbitrary code via deserialization of session data, which overwrites arbitrary global variables, as demonstrated by calling session_decode on a string…

  • CVE-2023-50252HigDec 12, 2023
    risk 0.02cvss 8.3epss 0.24

    php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `` tag that references an `` tag, it merges the attributes from the `` tag to the `` tag. The problem pops up especially when the `href` attribute from the…

  • CVE-2025-57773CriAug 25, 2025
    risk 0.01cvss 9.8epss 0.08

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files.…

  • CVE-2020-28032CriNov 2, 2020
    risk 0.01cvss 9.8epss 0.16

    WordPress before 5.5.2 mishandles deserialization requests in wp-includes/Requests/Utility/FilteredIterator.php.