CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,323)
page 158 of 167| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-35815 | Low | 0.23 | 3.5 | 0.01 | Apr 28, 2025 | DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data. | ||
| CVE-2023-35814 | Low | 0.23 | 3.5 | 0.01 | Apr 28, 2025 | DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms. | ||
| CVE-2026-5473 | Med | 0.22 | 4.5 | 0.00 | Apr 3, 2026 | A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The… | ||
| CVE-2024-27281 | Med | 0.22 | 4.5 | 0.02 | May 14, 2024 | An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the… | ||
| CVE-2023-34382 | Med | 0.22 | 4.4 | 0.01 | Dec 19, 2023 | Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from… | ||
| CVE-2022-29615 | Low | 0.22 | 3.4 | 0.00 | Jun 14, 2022 | SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x. | ||
| CVE-2019-16774 | Med | 0.22 | 4.4 | 0.01 | Dec 12, 2019 | In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. | ||
| CVE-2019-12760 | Low | 0.22 | 3.3 | 0.02 | Jun 6, 2019 | A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to… | ||
| CVE-2023-3360 | Low | 0.21 | 3.3 | 0.00 | Sep 2, 2026 | The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog. | ||
| CVE-2026-44501 | Med | 0.21 | 4.3 | 0.00 | May 14, 2026 | DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This… | ||
| CVE-2024-29040 | Med | 0.21 | 4.3 | 0.00 | Jun 28, 2024 | This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this… | ||
| CVE-2026-59306 | Low | 0.20 | 3.1 | 0.00 | Aug 27, 2026 | Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6 | ||
| CVE-2025-15117 | Low | 0.20 | 3.1 | 0.00 | Dec 28, 2025 | A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer.java. Executing manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high… | ||
| CVE-2025-10252 | Low | 0.20 | 3.1 | 0.00 | Sep 11, 2025 | A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The attack is considered to have high… | ||
| CVE-2016-0750 | Med | 0.20 | 4.2 | 0.02 | Sep 11, 2018 | The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks. | ||
| CVE-2026-10532 | Low | 0.19 | — | 0.00 | Jun 1, 2026 | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer… | ||
| CVE-2026-9828 | Low | 0.19 | — | 0.01 | May 28, 2026 | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or… | ||
| CVE-2026-5507 | Med | 0.19 | 4.0 | 0.00 | Apr 9, 2026 | When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the… | ||
| CVE-2026-50522 | Cri | 0.18 | 9.8 | 0.03 | KEV | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| CVE-2024-6525 | Low | 0.18 | 2.7 | 0.03 | Jul 5, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The… |
- risk 0.23cvss 3.5epss 0.01
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
- risk 0.23cvss 3.5epss 0.01
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
- risk 0.22cvss 4.5epss 0.00
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The…
- risk 0.22cvss 4.5epss 0.02
An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the…
- risk 0.22cvss 4.4epss 0.01
Deserialization of Untrusted Data vulnerability in weDevs Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy.This issue affects Dokan – Best WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: from…
- risk 0.22cvss 3.4epss 0.00
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.
- risk 0.22cvss 4.4epss 0.01
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
- risk 0.22cvss 3.3epss 0.02
A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to…
- risk 0.21cvss 3.3epss 0.00
The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.
- risk 0.21cvss 4.3epss 0.00
DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This…
- risk 0.21cvss 4.3epss 0.00
This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this…
- risk 0.20cvss 3.1epss 0.00
Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
- risk 0.20cvss 3.1epss 0.00
A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer.java. Executing manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high…
- risk 0.20cvss 3.1epss 0.00
A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only be done within the local network. The attack is considered to have high…
- risk 0.20cvss 4.2epss 0.02
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
- risk 0.19cvss —epss 0.00
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer…
- risk 0.19cvss —epss 0.01
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or…
- risk 0.19cvss 4.0epss 0.00
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability to inject a crafted session into the…
- risk 0.18cvss 9.8epss 0.03
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.18cvss 2.7epss 0.03
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The…