CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 64 of 66
- CVE-2026-66805HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-66808HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-66909CRITICALCVSS 9.8EG 9.82026-08-06
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a ma…
- CVE-2026-67260HIGHCVSS 7.3EG 7.32026-08-12
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who con…
- CVE-2026-67399CRITICALCVSS 9.3EG 9.32026-09-14
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
- CVE-2026-67579HIGHCVSS 7.4EG 7.42026-08-12
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the da…
- CVE-2026-67587HIGHCVSS 8.8EG 8.82026-08-12
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `…
- CVE-2026-6857HIGHCVSS 7.5EG 7.52026-04-22
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading …
- CVE-2026-68756MEDIUMCVSS 6.6EG 6.62026-08-12
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
- CVE-2026-68771CRITICALCVSS 9.8EG 9.82026-07-31
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserializ…
- CVE-2026-68772HIGHCVSS 8.0EG 8.02026-08-07
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attacker…
- CVE-2026-69098CRITICALCVSS 9.8EG 9.82026-08-04
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ …
- CVE-2026-69659MEDIUMCVSS 5.5EG 5.52026-08-09
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:afte…
- CVE-2026-69694HIGHCVSS 7.0EG 7.02026-09-08
Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69836CRITICALCVSS 10.0EG 10.02026-08-20
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-70321HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-70416CRITICALCVSS 10.0EG 10.02026-09-16
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
- CVE-2026-70426CRITICALCVSS 9.0EG 9.02026-08-05
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting des…
- CVE-2026-70554CRITICALCVSS 9.8EG 9.82026-08-04
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without valida…
- CVE-2026-71281HIGHCVSS 8.8EG 8.82026-08-05
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=…
- CVE-2026-71294HIGHCVSS 7.6EG 7.62026-08-05
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is pas…
- CVE-2026-71374CRITICALCVSS 9.8EG 9.82026-09-08
Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 throu…
- CVE-2026-71513HIGHCVSS 8.8EG 8.82026-08-22
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables ou…
- CVE-2026-71558CRITICALCVSS 9.8EG 9.82026-08-07
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer dese…
- CVE-2026-71559HIGHCVSS 7.5EG 7.52026-08-07
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This i…
- CVE-2026-71560CRITICALCVSS 9.1EG 9.12026-08-07
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an …
- CVE-2026-71981HIGHCVSS 8.8EG 8.82026-09-01
Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout hand…
- CVE-2026-72649HIGHCVSS 8.8EG 8.82026-09-01
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logi…
- CVE-2026-7301CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
- CVE-2026-7304CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
- CVE-2026-7317MEDIUMCVSS 5.0EG 5.02026-04-28
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The …
- CVE-2026-73325HIGHCVSS 7.8EG 7.82026-08-12
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized…
- CVE-2026-73341CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
- CVE-2026-73364CRITICALCVSS 9.8EG 9.82026-08-19
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
- CVE-2026-73366CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
- CVE-2026-73376CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
- CVE-2026-73380CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
- CVE-2026-73389CRITICALCVSS 9.8EG 9.82026-08-19
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
- CVE-2026-73397CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
- CVE-2026-73699HIGHCVSS 7.2EG 7.22026-09-10
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional…
- CVE-2026-73993CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- CVE-2026-74012HIGHCVSS 8.8EG 8.82026-08-18
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.
- CVE-2026-7566MEDIUMCVSS 6.6EG 6.62026-06-06
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it possible for authenticated attackers, …
- CVE-2026-7584HIGHCVSS 7.8EG 7.82026-05-01
The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names f…
- CVE-2026-7597MEDIUMCVSS 6.3EG 6.32026-05-01
A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem0/vector_stores/faiss.py. Performing a manipulation results in deserialization. It is possible to initiate the attack r…
- CVE-2026-75987HIGHCVSS 7.3EG 7.32026-08-19
A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remo…
- CVE-2026-7635HIGHCVSS 8.1EG 8.12026-05-13
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the…
- CVE-2026-7637CRITICALCVSS 9.8EG 9.82026-05-20
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attac…
- CVE-2026-76395HIGHCVSS 8.8EG 8.82026-08-19
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is p…
- CVE-2026-76404CRITICALCVSS 9.1EG 9.12026-08-19
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's cre…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →