CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 56 of 66
- CVE-2026-31221HIGHCVSS 7.8EG 7.82026-05-12
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model sta…
- CVE-2026-31222HIGHCVSS 8.8EG 8.82026-05-12
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.load() without enabling the security-restr…
- CVE-2026-31223HIGHCVSS 8.8EG 8.82026-05-12
The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler models using the unsafe pickle.load() func…
- CVE-2026-31224HIGHCVSS 8.8EG 8.82026-05-12
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight files using torch.load() without enablin…
- CVE-2026-31229CRITICALCVSS 9.8EG 9.82026-05-12
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., model.pt) during robus…
- CVE-2026-31232HIGHCVSS 8.8EG 8.82026-05-12
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directo…
- CVE-2026-31234CRITICALCVSS 9.8EG 9.82026-05-12
Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for distributed task coordination, lacks authentication and authorization controls, allowing an…
- CVE-2026-31235CRITICALCVSS 9.8EG 9.82026-05-12
The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The class uses Python's pickle module to deserialize data received via a multiprocessing queu…
- CVE-2026-31237CRITICALCVSS 9.8EG 9.82026-05-12
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines the file format. If…
- CVE-2026-31238CRITICALCVSS 9.8EG 9.82026-05-12
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads model weight files using torch.load() with…
- CVE-2026-31239CRITICALCVSS 9.8EG 9.82026-05-12
The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to load the pytorch_mod…
- CVE-2026-31249HIGHCVSS 7.3EG 7.32026-05-11
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embedd…
- CVE-2026-31250HIGHCVSS 7.3EG 7.32026-05-11
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) f…
- CVE-2026-31253HIGHCVSS 7.3EG 7.32026-05-11
The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in ch…
- CVE-2026-3199HIGHCVSS 8.8EG 8.82026-04-08
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreati…
- CVE-2026-32184HIGHCVSS 7.8EG 7.82026-04-14
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.
- CVE-2026-32192HIGHCVSS 7.8EG 7.82026-04-14
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
- CVE-2026-32355HIGHCVSS 8.8EG 8.82026-03-13
Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.
- CVE-2026-3245HIGHCVSS 7.5EG 7.52026-08-02
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
- CVE-2026-32465HIGHCVSS 8.8EG 8.82026-08-18
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
- CVE-2026-32470CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- CVE-2026-32484HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.
- CVE-2026-32502CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.
- CVE-2026-32506MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
- CVE-2026-32507MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4.
- CVE-2026-32508MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.
- CVE-2026-32509MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
- CVE-2026-32510MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a through < 1.3.
- CVE-2026-32511MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7.
- CVE-2026-32512CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.
- CVE-2026-32513HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7.
- CVE-2026-32563CRITICALCVSS 9.8EG 9.82026-08-24
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
- CVE-2026-32590HIGHCVSS 8.8EG 8.82026-04-08
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on…
- CVE-2026-3296CRITICALCVSS 9.8EG 9.82026-04-08
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php f…
- CVE-2026-33110HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-33112HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-33233HIGHCVSS 7.6EG 7.62026-05-19
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache bytes using pickle.loads without integrity/a…
- CVE-2026-33264CRITICALCVSS 9.8EG 9.82026-07-07
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain r…
- CVE-2026-3328HIGHCVSS 7.2EG 7.22026-03-26
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's …
- CVE-2026-33337HIGHCVSS 7.5EG 7.52026-04-17
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descr…
- CVE-2026-33439CRITICALCVSS 9.8EG 9.82026-04-07
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP p…
- CVE-2026-33454CRITICALCVSS 9.4EG 9.42026-04-27
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not con…
- CVE-2026-3357HIGHCVSS 8.8EG 8.82026-04-08
IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
- CVE-2026-33701CRITICALCVSS 9.8EG 9.82026-03-27
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data withou…
- CVE-2026-33725HIGHCVSS 7.2EG 7.22026-03-27
Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve…
- CVE-2026-33728CRITICALCVSS 9.8EG 9.82026-03-27
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JD…
- CVE-2026-33819CRITICALCVSS 10.0EG 10.02026-04-23
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
- CVE-2026-33858HIGHCVSS 8.8EG 8.82026-04-13
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. …
- CVE-2026-33942CRITICALCVSS 9.8EG 9.82026-03-26
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unserialize() to restore OAuth token state from cache or storage, with allowed…
- CVE-2026-34084CRITICALCVSS 9.8EG 9.82026-05-05
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load(…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →