← Back
CWE-502

3,196 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently verifying that the resulting data will be valid.

JSON object

Loading...

CVEs (3,196)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1James Server
May 13, 2026
Oct 20, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only o...Show more
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can only be used for privilege escalation. Release 3.0.1 upgrades the incriminated library.Show less
1Pulpproject
1Qpid
May 13, 2026
Oct 18, 2017
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted messag...Show more
The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pickle processing problem in pulp.Show less
1Apache
1Openmeetings
May 13, 2026
Oct 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
4Canonical
DebianRedhat+1 more
9Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+6 more
May 13, 2026
Oct 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects c...Show more
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.Show less
1Redhat
1Jboss Enterprise Application Platform
Aug 13, 2026
Oct 4, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it perfor...Show more
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.Show less
1Google
1Android
May 13, 2026
Oct 4, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.
1Branaghgroup
1Ers Data System
May 13, 2026
Sep 30, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserialization.
1Zte
6Nr8000tr Firmware
Nr8120 FirmwareNr8120a Firmware+3 more
May 13, 2026
Sep 28, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the...Show more
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.Show less
1Kaltura
1Kaltura Server
May 13, 2026
Sep 19, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
3Apache
CiscoNetapp
7Digital Media Manager
Hosted Collaboration SolutionMedia Experience Engine+4 more
Apr 21, 2026
Sep 15, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code...Show more
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.Show less
1Apache
1Spark
May 13, 2026
Sep 13, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to arbit...Show more
In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to arbitrary code execution by an attacker with access to any user account on the local machine. It does not affect apps run by spark-submit or spark-shell. The attacker would be able to execute code as the user that ran the Spark application. Users are encouraged to update to version 2.2.0 or later.Show less
1Apache
1Brooklyn
May 13, 2026
Sep 13, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration in Brooklyn before 0...Show more
Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration in Brooklyn before 0.10.0, SnakeYAML will allow unmarshalling to any Java type available on the classpath. This could provide an authenticated user with a means to cause the JVM running Brooklyn to load and run Java code without detection by Brooklyn. Such code would have the privileges of the Java process running Brooklyn, including the ability to open files and network connections, and execute system commands. There is known to be a proof-of-concept exploit using this vulnerability.Show less
1Crushftp
1Crushftp
May 13, 2026
Aug 30, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
1Synology
1Photo Station
May 13, 2026
Aug 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.
1Nancyfx
1Nancy
May 13, 2026
Jul 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.
1Plug Project
1Plug
May 13, 2026
Jul 17, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
1Akka
1Akka
May 13, 2026
Jul 17, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
1Apache
1Wicket
May 13, 2026
Jul 17, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFile...Show more
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.Show less
1Sap
1Netweaver
May 2, 2025
Jul 12, 2017
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804...Show more
SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object in a request to metadatauploader, aka SAP Security Note 2399804. NOTE: The vendor states that the devserver package of Visual Composer deserializes a malicious object that may cause legitimate users accessing a service, either by crashing or flooding the service.Show less
1Php
1Php
May 13, 2026
Jul 10, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an em...Show more
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wddx.c.Show less