VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 149 of 156
  • CVE-2026-33264CriJul 7, 2026
    risk 0.00cvss 9.8epss 0.01

    A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server /…

  • CVE-2026-46590HigJul 6, 2026
    risk 0.00cvss 8.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and…

  • CVE-2026-43867CriJul 6, 2026
    risk 0.00cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleManager.deserializeMetadata() reads that…

  • CVE-2026-43865HigJul 6, 2026
    risk 0.00cvss 8.1epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself -…

  • CVE-2026-42527HigJul 6, 2026
    risk 0.00cvss 8.1epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*', or the no-'javax.**' variant in the…

  • CVE-2026-14723MedJul 5, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/scripts/analyse_cache.py of the component Cache Handler. This manipulation of the argument sys.argv[1] causes deserialization. The attack can only be executed…

  • CVE-2026-57677CriJul 2, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

  • CVE-2026-57621CriJul 2, 2026
    risk 0.00cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

  • CVE-2026-56037HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.

  • CVE-2026-27414HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.

  • CVE-2026-27060HigJul 2, 2026
    risk 0.00cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This issue affects ARMember Premium: from n/a before 7.6.

  • CVE-2026-51947CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this…

  • CVE-2026-58127CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.01

    PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and…

  • CVE-2026-58126CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.01

    PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication…

  • CVE-2026-24251HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information…

  • CVE-2026-24250HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24247HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24245HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24244HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24243HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.