CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,290 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 66 of 66
- CVE-2026-84099HIGHCVSS 8.1EG 8.12026-09-12
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to injec…
- CVE-2026-84202HIGHCVSS 8.8EG 8.82026-09-01
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files t…
- CVE-2026-84646MEDIUMCVSS 4.3EG 4.32026-09-02
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
- CVE-2026-84647HIGHCVSS 8.8EG 8.82026-09-02
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to t…
- CVE-2026-84650HIGHCVSS 8.8EG 8.82026-09-02
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, t…
- CVE-2026-84670HIGHCVSS 8.8EG 8.82026-09-02
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers wi…
- CVE-2026-84752HIGHCVSS 8.8EG 8.82026-09-03
Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
- CVE-2026-84753CRITICALCVSS 9.8EG 9.82026-09-03
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
- CVE-2026-8476CRITICALCVSS 9.9EG 9.92026-07-17
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from dis…
- CVE-2026-84832HIGHCVSS 8.6EG 8.62026-09-03
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privil…
- CVE-2026-84834CRITICALCVSS 9.8EG 9.82026-09-03
Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
- CVE-2026-85017HIGHCVSS 7.5EG 7.52026-09-20
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with…
- CVE-2026-8612MEDIUMCVSS 5.3EG 5.32026-05-15
WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit cache backend, WWW::Mechanize::Cached constru…
- CVE-2026-86404HIGHCVSS 8.8EG 8.82026-09-07
EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() metho…
- CVE-2026-87083MEDIUMCVSS 5.5EG 5.52026-09-09
A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to de…
- CVE-2026-8727HIGHCVSS 7.1EG 7.12026-05-19
The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution o…
- CVE-2026-8735MEDIUMCVSS 6.3EG 6.32026-05-17
A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuery Interface. Such manipulation leads to deserialization. The attack…
- CVE-2026-8751HIGHCVSS 7.3EG 7.32026-05-17
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Handler. Performing a manipulation results in deserialization…
- CVE-2026-87719CRITICALCVSS 9.9EG 9.92026-09-12
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced …
- CVE-2026-87874HIGHCVSS 8.1EG 8.12026-09-09
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcac…
- CVE-2026-87930HIGHCVSS 8.1EG 8.12026-09-09
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to t…
- CVE-2026-90490MEDIUMCVSS 6.3EG 6.32026-09-13
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remotel…
- CVE-2026-90575LOWCVSS 3.7EG 3.72026-09-13
A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It …
- CVE-2026-90614MEDIUMCVSS 6.3EG 6.32026-09-14
A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend.…
- CVE-2026-90777HIGHCVSS 8.8EG 8.82026-09-13
ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code durin…
- CVE-2026-90919CRITICALCVSS 9.8EG 9.82026-09-14
LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config …
- CVE-2026-91842MEDIUMCVSS 4.1EG 4.12026-09-15
A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to …
- CVE-2026-91939CRITICALCVSS 9.8EG 9.82026-09-15
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can expl…
- CVE-2026-92785HIGHCVSS 8.1EG 8.12026-09-16
Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending c…
- CVE-2026-9291HIGHCVSS 7.1EG 7.12026-05-22
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine …
- CVE-2026-9319CRITICALCVSS 9.0EG 9.02026-06-01
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
- CVE-2026-9330HIGHCVSS 8.5EG 8.52026-06-01
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remote code execution via a crafted HTTP req…
- CVE-2026-93467CRITICALCVSS 9.8EG 9.82026-09-18
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
- CVE-2026-93872HIGHCVSS 7.5EG 7.52026-09-18
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentia…
- CVE-2026-94091MEDIUMCVSS 5.5EG 5.52026-09-20
A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is poss…
- CVE-2026-94092MEDIUMCVSS 5.5EG 5.52026-09-20
A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotel…
- CVE-2026-94093MEDIUMCVSS 6.3EG 6.32026-09-20
A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possibl…
- CVE-2026-9497MEDIUMCVSS 6.3EG 6.32026-05-25
A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deserialization. It is possible to initiate the a…
- CVE-2026-9691CRITICALCVSS 9.8EG 9.82026-06-15
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
- CVE-2026-9828LOWCVSS 2.9EG 2.92026-05-28
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serial…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →