← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Dubbo
Jun 17, 2026
Jul 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicio...Show more
This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some malicious code. More details can be found below.Show less
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
Jun 17, 2026
Jul 9, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially c...Show more
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 176677.Show less
1Atlassian
2Jira
Jira Software Data Center
Jun 17, 2026
Jul 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server an...Show more
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if they were able to exploit a server side template injection vulnerability. The affected versions are before version 7.13.0, from version 8.0.0 before 8.5.0, and from version 8.6.0 before version 8.8.1.Show less
1Jenkins
1Kubernetes Ci
Jun 17, 2026
Jul 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
1Beakerbrowser
1Beaker
Nov 21, 2024
Jun 26, 2020
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
1Redhat
1Wildfly
Jun 17, 2026
Jun 22, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly...Show more
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.Show less
1Tendenci
1Tendenci
Jun 17, 2026
Jun 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Tendenci 12.0.10 allows unrestricted deserialization in apps\helpdesk\views\staff.py.
1Squirrelmail
1Squirrelmail
Jun 17, 2026
Jun 20, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not sa...Show more
compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup or __destruct), and any attack-relevant classes must be declared before unserialize is called (or must be autoloaded).Show less
1Squirrelmail
1Squirrelmail
Jun 17, 2026
Jun 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php.
3Debian
OpensuseRubyonrails
3Debian Linux
LeapRails
Jun 17, 2026
Jun 19, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in...Show more
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.Show less
3Debian
OpensuseRubyonrails
4Backports Sle
Debian LinuxLeap+1 more
Jun 17, 2026
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
4Debian
FasterxmlNetapp+1 more
15Active Iq Unified Manager
Agile PlmAgile Product Lifecycle Management+12 more
Aug 25, 2026
Jun 16, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).
3Fasterxml
NetappOracle
13Active Iq Unified Manager
Agile PlmAgile Product Lifecycle Management+10 more
Aug 25, 2026
Jun 14, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).
4Debian
FasterxmlNetapp+1 more
14Active Iq Unified Manager
Agile PlmAgile Product Lifecycle Management+11 more
Aug 25, 2026
Jun 14, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).
4Debian
FasterxmlNetapp+1 more
16Active Iq Unified Manager
Agile PlmAgile Product Lifecycle Management+13 more
Aug 25, 2026
Jun 14, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms....Show more
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).Show less
2Broadcom
Pivotal Software
2Spring Batch
Spring Batch
Sep 1, 2026
Jun 11, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". S...Show more
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". Spring Batch configures Jackson with global default typing enabled which means that through the previous exploit, arbitrary code could be executed if all of the following is true: * Spring Batch's Jackson support is being leveraged to serialize a job's ExecutionContext. * A malicious user gains write access to the data store used by the JobRepository (where the data to be deserialized is stored). In order to protect against this type of attack, Jackson prevents a set of untrusted gadget classes from being deserialized. Spring Batch should be proactive against blocking unknown "deserialization gadgets" when enabling default typing.Show less
1Google
1Android
Jun 17, 2026
Jun 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed....Show more
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139473816Show less
1Phpmussel Project
1Phpmussel
Jun 17, 2026
Jun 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested,...Show more
phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0.Show less
1Inductiveautomation
1Ignition Gateway
Jun 17, 2026
Jun 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 G...Show more
The affected product is vulnerable to the handling of serialized data. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.Show less
1Inductiveautomation
1Ignition Gateway
Jun 17, 2026
Jun 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9...Show more
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted data on the Ignition 8 Gateway (versions prior to 8.0.10) and Ignition 7 Gateway (versions prior to 7.9.14), allowing an attacker to obtain sensitive information.Show less