CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 61 of 66
- CVE-2026-53435HIGHCVSS 8.8EG 8.92026-06-10
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows the…
- CVE-2026-53805CRITICALCVSS 9.8EG 9.82026-06-17
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Pyth…
- CVE-2026-53874CRITICALCVSS 9.8EG 9.82026-06-17
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle …
- CVE-2026-53914CRITICALCVSS 9.8EG 9.82026-06-26
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
- CVE-2026-54071HIGHCVSS 7.8EG 7.82026-07-10
BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values…
- CVE-2026-54117CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-54118CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-54194CRITICALCVSS 9.8EG 9.82026-06-17
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
- CVE-2026-5426CRITICALCVSS 9.1EG 9.12026-04-16
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState…
- CVE-2026-54469HIGHCVSS 8.8EG 8.82026-07-10
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary comma…
- CVE-2026-54499HIGHCVSS 7.5EG 7.52026-06-19
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., …
- CVE-2026-54512HIGHCVSS 8.1EG 8.12026-06-23
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechan…
- CVE-2026-5473HIGHCVSS 7.0EG 7.02026-04-03
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requi…
- CVE-2026-54752CRITICALCVSS 9.6EG 9.62026-09-17
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_…
- CVE-2026-54806CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
- CVE-2026-55009HIGHCVSS 7.8EG 7.82026-07-14
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-5507MEDIUMCVSS 4.0EG 4.02026-04-09
When restoring a session from cache, a pointer from the serialized session data is used in a free operation without validation. An attacker who can poison the session cache could trigger an arbitrary free. Exploitation requires the ability…
- CVE-2026-55153HIGHCVSS 7.1EG 7.12026-07-01
mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will const…
- CVE-2026-55175HIGHCVSS 7.5EG 7.52026-07-10
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco mani…
- CVE-2026-55220CRITICALCVSS 9.3EG 9.32026-08-28
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspotim…
- CVE-2026-55223MEDIUMCVSS 6.3EG 6.32026-06-30
c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSour…
- CVE-2026-5536HIGHCVSS 7.3EG 7.32026-04-05
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_server.py of the component gRPC server. Executing a manipulation can lead to deserialization. The attack may be performed f…
- CVE-2026-55944CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
- CVE-2026-56031HIGHCVSS 8.1EG 8.12026-06-26
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
- CVE-2026-56032CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
- CVE-2026-56037HIGHCVSS 8.8EG 8.82026-07-02
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.
- CVE-2026-56053HIGHCVSS 8.8EG 8.82026-06-25
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
- CVE-2026-56055HIGHCVSS 8.8EG 8.82026-06-26
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
- CVE-2026-56057CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
- CVE-2026-56095HIGHCVSS 7.7EG 7.72026-08-25
The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object typ…
- CVE-2026-56121CRITICALCVSS 9.8EG 9.82026-06-24
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function…
- CVE-2026-56304MEDIUMCVSS 6.5EG 6.52026-06-20
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting mali…
- CVE-2026-5659MEDIUMCVSS 6.3EG 6.32026-04-06
A vulnerability was found in pytries datrie up to 0.8.3. The affected element is the function Trie.load/Trie.read/Trie.__setstate__ of the file src/datrie.pyx of the component trie File Handler. The manipulation results in deserialization.…
- CVE-2026-56700CRITICALCVSS 9.8EG 9.82026-07-01
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowe…
- CVE-2026-57371HIGHCVSS 8.8EG 8.82026-07-13
Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.
- CVE-2026-57516HIGHCVSS 8.8EG 8.82026-07-01
Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decod…
- CVE-2026-57527HIGHCVSS 8.8EG 8.82026-06-26
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java…
- CVE-2026-57621CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
- CVE-2026-57677CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
- CVE-2026-57713HIGHCVSS 8.8EG 8.82026-07-13
Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.
- CVE-2026-57724CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- CVE-2026-57738CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- CVE-2026-57744CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
- CVE-2026-57770CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
- CVE-2026-57822MEDIUMCVSS 6.5EG 6.52026-09-10
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserializa…
- CVE-2026-57859HIGHCVSS 7.5EG 7.52026-07-30
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the use…
- CVE-2026-58025CRITICALCVSS 9.8EG 9.82026-07-01
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php.…
- CVE-2026-58076HIGHCVSS 8.8EG 8.82026-08-12
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imp…
- CVE-2026-58126CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.e…
- CVE-2026-58127CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObje…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →