CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
3,465 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 7 of 70
- CVE-2026-65552CRITICALCVSS 9.8EG 9.82026-08-06
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
- CVE-2026-28139CRITICALCVSS 9.8EG 9.82026-08-06
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
- CVE-2026-66909CRITICALCVSS 9.8EG 9.82026-08-06
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a ma…
- CVE-2026-61484CRITICALCVSS 9.8EG 9.82026-08-05
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. User…
- CVE-2026-70554CRITICALCVSS 9.8EG 9.82026-08-04
MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without valida…
- CVE-2026-69098CRITICALCVSS 9.8EG 9.82026-08-04
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ …
- CVE-2026-68771CRITICALCVSS 9.8EG 9.82026-07-31
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserializ…
- CVE-2026-15969CRITICALCVSS 9.8EG 9.82026-07-30
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.
- CVE-2026-15976CRITICALCVSS 9.8EG 9.82026-07-30
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization o…
- CVE-2026-12118CRITICALCVSS 9.8EG 9.82026-07-30
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
- CVE-2026-65883CRITICALCVSS 9.8EG 9.82026-07-29
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
- CVE-2026-14512CRITICALCVSS 9.8EG 9.82026-07-28
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.
- CVE-2026-14974CRITICALCVSS 9.8EG 9.82026-07-28
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
- CVE-2026-66713CRITICALCVSS 9.8EG 9.82026-07-28
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) a…
- CVE-2026-59940CRITICALCVSS 9.8EG 9.82026-07-24
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general d…
- CVE-2026-59544CRITICALCVSS 9.8EG 9.82026-07-23
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
- CVE-2026-60372CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-60367CRITICALCVSS 9.8EG 9.82026-07-22
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability all…
- CVE-2026-64606CRITICALCVSS 9.8EG 9.82026-07-21
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users a…
- CVE-2026-64608CRITICALCVSS 9.8EG 9.82026-07-21
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input w…
- CVE-2026-63767CRITICALCVSS 9.8EG 9.82026-07-20
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ…
- CVE-2026-24227CRITICALCVSS 9.8EG 9.82026-07-14
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution.
- CVE-2026-55944CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
- CVE-2026-54118CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-54117CRITICALCVSS 9.8EG 9.82026-07-14
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-59518CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
- CVE-2026-57770CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
- CVE-2026-57744CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
- CVE-2026-57738CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.
- CVE-2026-57724CRITICALCVSS 9.8EG 9.82026-07-13
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.
- CVE-2026-33264CRITICALCVSS 9.8EG 9.82026-07-07
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain r…
- CVE-2026-43867CRITICALCVSS 9.8EG 9.82026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. AwsSecretsManagerKeyLifecycleMa…
- CVE-2026-12481CRITICALCVSS 9.8EG 9.82026-07-03
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the…
- CVE-2026-57621CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
- CVE-2026-57677CRITICALCVSS 9.8EG 9.82026-07-02
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.
- CVE-2026-51947CRITICALCVSS 9.8EG 9.82026-07-01
An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services…
- CVE-2026-58127CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObje…
- CVE-2026-58126CRITICALCVSS 9.8EG 9.82026-07-01
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.e…
- CVE-2026-58025CRITICALCVSS 9.8EG 9.82026-07-01
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php.…
- CVE-2026-56700CRITICALCVSS 9.8EG 9.82026-07-01
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowe…
- CVE-2026-7871CRITICALCVSS 9.8EG 9.82026-06-30
IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.
- CVE-2026-56032CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
- CVE-2026-56057CRITICALCVSS 9.8EG 9.82026-06-26
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
- CVE-2026-53914CRITICALCVSS 9.8EG 9.82026-06-26
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
- CVE-2026-56121CRITICALCVSS 9.8EG 9.82026-06-24
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function…
- CVE-2026-8024CRITICALCVSS 9.8EG 9.82026-06-18
A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.
- CVE-2026-53805CRITICALCVSS 9.8EG 9.82026-06-17
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Pyth…
- CVE-2026-53874CRITICALCVSS 9.8EG 9.82026-06-17
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle …
- CVE-2025-71321CRITICALCVSS 9.8EG 9.82026-06-17
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critic…
- CVE-2026-49108CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →