CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,159 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 55 of 64
- CVE-2026-28074CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a through <= 1.4.0.
- CVE-2026-28105CRITICALCVSS 9.8EG 9.82026-03-05
Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a through <= 1.7.7.
- CVE-2026-28138HIGHCVSS 7.2EG 7.22026-02-26
Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.
- CVE-2026-28139CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
- CVE-2026-28149CRITICALCVSS 9.8EG 9.82026-08-13
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
- CVE-2026-28176HIGHCVSS 8.8EG 8.82026-08-13
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
- CVE-2026-28220CRITICALCVSS 9.1EG 9.12026-07-20
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the clu…
- CVE-2026-28277HIGHCVSS 7.2EG 7.22026-03-05
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstru…
- CVE-2026-2898MEDIUMCVSS 6.5EG 6.52026-02-22
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account resul…
- CVE-2026-29109HIGHCVSS 7.2EG 7.22026-03-20
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component tha…
- CVE-2026-2970HIGHCVSS 7.5EG 7.52026-02-23
A vulnerability has been found in datapizza-labs datapizza-ai 0.0.2. Affected by this vulnerability is the function RedisCache of the file datapizza-ai-cache/redis/datapizza/cache/redis/cache.py. Such manipulation leads to deserialization.…
- CVE-2026-29782HIGHCVSS 7.2EG 7.22026-04-02
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permissions = true). It loads a record from t…
- CVE-2026-3017HIGHCVSS 7.2EG 7.22026-04-14
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import…
- CVE-2026-3048MEDIUMCVSS 5.1EG 5.12026-05-11
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP s…
- CVE-2026-3059CRITICALCVSS 9.8EG 9.82026-03-12
SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2026-3060CRITICALCVSS 9.8EG 9.82026-03-12
SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.
- CVE-2026-3071HIGHCVSS 8.4EG 8.42026-02-26
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.
- CVE-2026-31072CRITICALCVSS 9.8EG 9.82026-05-19
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantia…
- CVE-2026-31214CRITICALCVSS 9.8EG 9.82026-05-12
The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load() to process PyTor…
- CVE-2026-31218HIGHCVSS 8.8EG 8.82026-05-12
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading a model state dicti…
- CVE-2026-31219HIGHCVSS 8.8EG 8.82026-05-12
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When a user provides a single mo…
- CVE-2026-31221HIGHCVSS 7.8EG 7.82026-05-12
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model sta…
- CVE-2026-31222HIGHCVSS 8.8EG 8.82026-05-12
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.load() without enabling the security-restr…
- CVE-2026-31223HIGHCVSS 8.8EG 8.82026-05-12
The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler models using the unsafe pickle.load() func…
- CVE-2026-31224HIGHCVSS 8.8EG 8.82026-05-12
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight files using torch.load() without enablin…
- CVE-2026-31229CRITICALCVSS 9.8EG 9.82026-05-12
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., model.pt) during robus…
- CVE-2026-31232HIGHCVSS 8.8EG 8.82026-05-12
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directo…
- CVE-2026-31234CRITICALCVSS 9.8EG 9.82026-05-12
Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for distributed task coordination, lacks authentication and authorization controls, allowing an…
- CVE-2026-31235CRITICALCVSS 9.8EG 9.82026-05-12
The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The class uses Python's pickle module to deserialize data received via a multiprocessing queu…
- CVE-2026-31237CRITICALCVSS 9.8EG 9.82026-05-12
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines the file format. If…
- CVE-2026-31238CRITICALCVSS 9.8EG 9.82026-05-12
The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads model weight files using torch.load() with…
- CVE-2026-31239CRITICALCVSS 9.8EG 9.82026-05-12
The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to load the pytorch_mod…
- CVE-2026-31249HIGHCVSS 7.3EG 7.32026-05-11
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embedd…
- CVE-2026-31250HIGHCVSS 7.3EG 7.32026-05-11
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) f…
- CVE-2026-31253HIGHCVSS 7.3EG 7.32026-05-11
The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in ch…
- CVE-2026-3199CRITICALCVSS 9.4EG 9.42026-04-08
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreati…
- CVE-2026-32184HIGHCVSS 7.8EG 7.82026-04-14
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.
- CVE-2026-32192HIGHCVSS 7.8EG 7.82026-04-14
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
- CVE-2026-32355HIGHCVSS 8.8EG 8.82026-03-13
Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.
- CVE-2026-3245HIGHCVSS 7.5EG 7.52026-08-02
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
- CVE-2026-32465HIGHCVSS 8.8EG 8.82026-08-18
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
- CVE-2026-32470CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- CVE-2026-32484HIGHCVSS 8.8EG 8.82026-03-25
Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through <= 1.6.26.
- CVE-2026-32502CRITICALCVSS 9.8EG 9.82026-03-25
Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.
- CVE-2026-32506MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
- CVE-2026-32507MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4.
- CVE-2026-32508MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.
- CVE-2026-32509MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
- CVE-2026-32510MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a through < 1.3.
- CVE-2026-32511MEDIUMCVSS 5.4EG 5.42026-03-25
Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →