CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,159 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 62 of 64
- CVE-2026-65556CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
- CVE-2026-65571CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
- CVE-2026-65572CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
- CVE-2026-65573CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
- CVE-2026-65574CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
- CVE-2026-65575CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
- CVE-2026-65576CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
- CVE-2026-65577CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
- CVE-2026-65578CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
- CVE-2026-65579CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
- CVE-2026-65581CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
- CVE-2026-65617HIGHCVSS 8.8EG 8.82026-07-27
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
- CVE-2026-65658HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65663HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65665HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-65815HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- CVE-2026-65883CRITICALCVSS 9.8EG 9.82026-07-29
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
- CVE-2026-66256HIGHCVSS 7.2EG 7.22026-08-13
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger …
- CVE-2026-66583CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
- CVE-2026-66620HIGHCVSS 7.2EG 7.22026-08-18
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
- CVE-2026-66650CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
- CVE-2026-66672CRITICALCVSS 9.8EG 9.82026-08-20
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
- CVE-2026-66713CRITICALCVSS 9.8EG 9.82026-07-28
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) a…
- CVE-2026-66805HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-66808HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-66909CRITICALCVSS 9.8EG 9.82026-08-06
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a ma…
- CVE-2026-67260HIGHCVSS 7.3EG 7.32026-08-12
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who con…
- CVE-2026-67579HIGHCVSS 7.4EG 7.42026-08-12
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the da…
- CVE-2026-67587HIGHCVSS 8.8EG 8.82026-08-12
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `…
- CVE-2026-6857HIGHCVSS 7.5EG 7.52026-04-22
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading …
- CVE-2026-68756MEDIUMCVSS 6.6EG 6.62026-08-12
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
- CVE-2026-68771CRITICALCVSS 9.8EG 9.82026-07-31
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserializ…
- CVE-2026-68772HIGHCVSS 8.0EG 8.02026-08-07
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attacker…
- CVE-2026-69098CRITICALCVSS 9.8EG 9.82026-08-04
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ …
- CVE-2026-69659MEDIUMCVSS 5.5EG 5.52026-08-09
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:afte…
- CVE-2026-69836CRITICALCVSS 10.0EG 10.02026-08-20
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- CVE-2026-70321HIGHCVSS 8.8EG 8.82026-08-11
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-70426CRITICALCVSS 9.0EG 9.02026-08-05
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting des…
- CVE-2026-70554CRITICALCVSS 9.8EG 9.82026-08-04
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without valida…
- CVE-2026-71281HIGHCVSS 8.8EG 8.82026-08-05
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=…
- CVE-2026-71294HIGHCVSS 7.6EG 7.62026-08-05
Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controllers/actions/CreateAction.php, a POST parameter obtained via (trim-only sanitization) is pas…
- CVE-2026-71513HIGHCVSS 8.8EG 8.82026-08-22
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables ou…
- CVE-2026-71558CRITICALCVSS 9.8EG 9.82026-08-07
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer dese…
- CVE-2026-71559HIGHCVSS 7.5EG 7.52026-08-07
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This i…
- CVE-2026-71560CRITICALCVSS 9.1EG 9.12026-08-07
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an …
- CVE-2026-7301CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the internet.
- CVE-2026-7304CRITICALCVSS 9.8EG 9.82026-05-18
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be deserialized without validation.
- CVE-2026-7317MEDIUMCVSS 5.0EG 5.02026-04-28
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The …
- CVE-2026-73325HIGHCVSS 7.8EG 7.82026-08-12
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized…
- CVE-2026-73341CRITICALCVSS 9.8EG 9.82026-08-18
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →