CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 59 of 66
- CVE-2026-42472CRITICALCVSS 9.8EG 9.82026-05-01
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object.
- CVE-2026-42473CRITICALCVSS 9.8EG 9.82026-05-01
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object.
- CVE-2026-42521MEDIUMCVSS 6.5EG 6.52026-04-29
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that…
- CVE-2026-42527HIGHCVSS 8.1EG 8.12026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with several Apache Camel components for defense-in-depth deserialization filtering ('java.**;javax.**;org.apache.camel.**;!*',…
- CVE-2026-4266MEDIUMCVSS 6.7EG 6.72026-03-30
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note…
- CVE-2026-42687HIGHCVSS 8.1EG 8.12026-06-15
Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
- CVE-2026-42778CRITICALCVSS 9.8EG 9.82026-05-01
The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of clas…
- CVE-2026-42779CRITICALCVSS 9.8EG 9.82026-05-01
The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primiti…
- CVE-2026-43633CRITICALCVSS 10.0EG 10.02026-05-19
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code…
- CVE-2026-4372HIGHCVSS 7.8EG 7.82026-05-24
A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implem…
- CVE-2026-43825HIGHCVSS 7.3EG 7.32026-07-06
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document categorization module; introduced in OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.des…
- CVE-2026-43865HIGHCVSS 8.1EG 8.12026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Cam…
- CVE-2026-43866HIGHCVSS 7.3EG 7.32026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms() in camel-jms - and the equivalent JmsBinding in camel-sjms - deserializes the payload of an incoming JMS ObjectMe…
- CVE-2026-43867CRITICALCVSS 9.8EG 9.82026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleMa…
- CVE-2026-44126CRITICALCVSS 9.2EG 9.22026-05-08
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object.
- CVE-2026-4416HIGHCVSS 7.8EG 7.82026-03-30
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escala…
- CVE-2026-44501MEDIUMCVSS 4.3EG 4.32026-05-14
DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity p…
- CVE-2026-44795HIGHCVSS 8.8EG 8.82026-06-22
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. …
- CVE-2026-44843HIGHCVSS 8.2EG 8.22026-05-26
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using over…
- CVE-2026-44901HIGHCVSS 8.4EG 8.42026-08-19
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a c…
- CVE-2026-44963CRITICALCVSS 9.4EG 9.42026-06-09
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
- CVE-2026-45034CRITICALCVSS 9.2EG 9.22026-06-08
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_stri…
- CVE-2026-45051CRITICALCVSS 9.2EG 9.22026-06-24
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInput…
- CVE-2026-45077HIGHCVSS 8.6EG 8.62026-05-27
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 …
- CVE-2026-45134HIGHCVSS 7.1EG 7.12026-05-27
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPro…
- CVE-2026-45162HIGHCVSS 8.0EG 8.02026-05-27
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restrict…
- CVE-2026-45247CRITICALCVSS 9.8EG 9.8⚠ KEV2026-05-26
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the C…
- CVE-2026-45360HIGHCVSS 7.3EG 7.32026-06-01
Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-r…
- CVE-2026-4538HIGHCVSS 7.8EG 7.82026-03-22
A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The e…
- CVE-2026-45484HIGHCVSS 8.8EG 8.82026-06-09
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45659CRITICALCVSS 8.8EG 9.0⚠ KEV2026-05-26
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-45794HIGHCVSS 7.7EG 7.72026-06-25
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory d…
- CVE-2026-45829CRITICALCVSS 10.0EG 10.02026-05-18
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_cod…
- CVE-2026-46386CRITICALCVSS 9.9EG 9.92026-06-26
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :mar…
- CVE-2026-46495CRITICALCVSS 9.2EG 9.22026-06-22
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authenti…
- CVE-2026-46590HIGHCVSS 8.8EG 8.82026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManag…
- CVE-2026-46607HIGHCVSS 7.8EG 7.82026-06-22
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db …
- CVE-2026-46725CRITICALCVSS 9.2EG 9.22026-05-19
The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to …
- CVE-2026-4703CRITICALCVSS 9.8EG 9.82026-08-22
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This ma…
- CVE-2026-47058HIGHCVSS 7.4EG 7.42026-07-21
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via mu…
- CVE-2026-47065CRITICALCVSS 9.8EG 9.82026-06-03
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), J…
- CVE-2026-47161HIGHCVSS 8.7EG 8.72026-05-27
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker who can reach the message broker ca…
- CVE-2026-47297HIGHCVSS 8.1EG 8.12026-09-08
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-4735HIGHCVSS 8.7EG 8.72026-03-24
Deserialization of Untrusted Data vulnerability in DTStack chunjun (chunjun-core/src/main/java/com/dtstack/chunjun/util modules). This vulnerability is associated with program files GsonUtil.Java. This issue affects chunjun: before 1.1…
- CVE-2026-47472HIGHCVSS 7.8EG 7.82026-07-14
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, infor…
- CVE-2026-47623HIGHCVSS 8.2EG 8.22026-08-04
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
- CVE-2026-47856MEDIUMCVSS 6.3EG 6.32026-08-26
Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7…
- CVE-2026-47864CRITICALCVSS 9.8EG 9.82026-08-27
SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serial…
- CVE-2026-47875CRITICALCVSS 9.8EG 9.82026-08-27
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not pr…
- CVE-2026-47878HIGHCVSS 7.3EG 7.32026-08-27
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →