GHSA-4jrv-ppp4-jm57HighCVSS 7.7

Deserialization of Untrusted Data in Gson

Published
May 3, 2022
Last Modified
June 8, 2026

🔗 CVE IDs covered (1)

📋 Description

The package com.google.code.gson:gson before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to denial of service attacks.

🎯 Affected products1

  • maven/com.google.code.gson:gson:< 2.8.9

🔗 References (10)