CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 60 of 66
- CVE-2026-48207CRITICALCVSS 9.8EG 9.82026-05-21
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if i…
- CVE-2026-48397HIGHCVSS 8.6EG 8.62026-08-11
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Ex…
- CVE-2026-48502HIGHCVSS 7.5EG 7.52026-06-22
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp exte…
- CVE-2026-4851CRITICALCVSS 9.8EG 9.82026-03-29
GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to execute code on them. …
- CVE-2026-48517HIGHCVSS 7.5EG 7.52026-06-22
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePackSerializerOptions.ThrowIfDeserializingTypeIsDisallowed(Type) as a safety check for dangero…
- CVE-2026-48560MEDIUMCVSS 5.4EG 5.42026-06-09
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-4860HIGHCVSS 7.3EG 7.32026-03-26
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the component API…
- CVE-2026-48775MEDIUMCVSS 6.8EG 6.82026-06-16
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint…
- CVE-2026-48853CRITICALCVSS 9.2EG 9.22026-06-15
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows …
- CVE-2026-48909CRITICALCVSS 9.5EG 9.52026-06-20
SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.
- CVE-2026-48917MEDIUMCVSS 6.6EG 6.62026-05-27
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
- CVE-2026-48919MEDIUMCVSS 6.6EG 6.62026-05-27
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
- CVE-2026-49075CRITICALCVSS 9.8EG 9.82026-06-17
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
- CVE-2026-49085CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- CVE-2026-49104CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
- CVE-2026-49105CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
- CVE-2026-49106CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.
- CVE-2026-49107CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
- CVE-2026-49108CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
- CVE-2026-49109CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.
- CVE-2026-49121CRITICALCVSS 9.8EG 9.82026-06-01
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary …
- CVE-2026-49286HIGHCVSS 8.1EG 8.12026-06-19
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrapper with a case-sensitive blacklist. PHP s…
- CVE-2026-49400LOWCVSS 3.3EG 3.32026-09-14
October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize(...))` and consumed it with `unserializ…
- CVE-2026-49740MEDIUMCVSS 6.3EG 6.32026-06-09
TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store …
- CVE-2026-49763CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
- CVE-2026-49765CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
- CVE-2026-49768CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
- CVE-2026-49769CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
- CVE-2026-49770CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
- CVE-2026-49781CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
- CVE-2026-49816HIGHCVSS 7.8EG 7.82026-08-19
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- CVE-2026-49817HIGHCVSS 7.8EG 7.82026-08-19
Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- CVE-2026-50076CRITICALCVSS 9.1EG 9.12026-06-04
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invok…
- CVE-2026-50509HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-50515CRITICALCVSS 9.9EG 9.92026-08-06
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
- CVE-2026-50517CRITICALCVSS 9.9EG 9.92026-07-24
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
- CVE-2026-50522CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-14
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-50589HIGHCVSS 7.5EG 7.52026-06-04
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
- CVE-2026-50632CRITICALCVSS 8.1EG 9.82026-06-12
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
- CVE-2026-50633CRITICALCVSS 8.1EG 9.82026-06-12
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. U…
- CVE-2026-50646HIGHCVSS 7.8EG 7.82026-07-14
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
- CVE-2026-50649HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
- CVE-2026-50652HIGHCVSS 7.5EG 7.52026-07-14
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
- CVE-2026-51106CRITICALCVSS 9.3EG 9.32026-08-26
An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component
- CVE-2026-5127HIGHCVSS 8.8EG 8.82026-05-08
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4.3.1 This is due to insuffic…
- CVE-2026-51368CRITICALCVSS 9.8EG 9.82026-08-25
An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint
- CVE-2026-51947CRITICALCVSS 9.8EG 9.82026-07-01
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services…
- CVE-2026-52706CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
- CVE-2026-52751HIGHCVSS 8.8EG 8.82026-06-10
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that…
- CVE-2026-52777CRITICALCVSS 9.4EG 9.42026-07-09
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →