VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 55 of 167
  • CVE-2020-8840CriFeb 10, 2020
    risk 0.59cvss 9.8epss 0.27

    FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

  • CVE-2016-1000027CriJan 2, 2020
    risk 0.59cvss 9.8epss 0.33

    Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required.…

  • CVE-2019-10867HigApr 4, 2019
    risk 0.59cvss 8.8epss 0.69

    An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/class/bulk-commit, which will make it possible to exploit the unserialize function when passing untrusted values in the data parameter to…

  • CVE-2018-20148CriDec 14, 2018
    risk 0.59cvss 9.8epss 0.27

    In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in…

  • CVE-2018-15616CriOct 17, 2018
    risk 0.59cvss 9.0epss 0.03

    A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0…

  • CVE-2018-8349HigAug 15, 2018
    risk 0.59cvss 8.8epss 0.23

    A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server…

  • CVE-2017-2292CriJun 30, 2017
    risk 0.59cvss 9.0epss 0.02

    Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-supplied MCollective…

  • CVE-2016-3415CriJan 18, 2017
    risk 0.59cvss 9.1epss 0.02

    Zimbra Collaboration before 8.7.0 allows remote attackers to conduct deserialization attacks via unspecified vectors, aka bug 102276.

  • CVE-2026-43633CriMay 19, 2026
    risk 0.58cvss 10.0epss 0.01

    HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code execution. Attackers can inject crafted…

  • CVE-2026-45829CriMay 18, 2026
    risk 0.58cvss 10.0epss 0.01

    A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in…

  • CVE-2026-25874CriApr 23, 2026
    risk 0.58cvss 9.8epss 0.01

    LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated…

  • CVE-2026-25632CriFeb 6, 2026
    risk 0.58cvss 10.0epss 0.01

    EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that…

  • CVE-2025-56005CriJan 20, 2026
    risk 0.58cvss 9.8epss 0.19

    An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because…

  • CVE-2025-47163HigJun 10, 2025
    risk 0.58cvss 8.8epss 0.20

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-32444CriApr 30, 2025
    risk 0.58cvss 10.0epss 0.02

    vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serialization over unsecured ZeroMQ…

  • CVE-2023-36039HigNov 14, 2023
    risk 0.58cvss 8.0epss 0.73

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-47248CriNov 9, 2023
    risk 0.58cvss 9.8epss 0.15

    Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example user-supplied input files). This…

  • CVE-2023-36756HigSep 12, 2023
    risk 0.58cvss 8.0epss 0.49

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-36745HigSep 12, 2023
    risk 0.58cvss 8.0epss 0.80

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-38181HigAug 8, 2023
    risk 0.58cvss 8.8epss 0.11

    Microsoft Exchange Server Spoofing Vulnerability