CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 53 of 58
- CVE-2026-33337HIGHCVSS 7.5EG 7.52026-04-17
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descr…
- CVE-2026-33439CRITICALCVSS 9.8EG 9.82026-04-07
Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP p…
- CVE-2026-33454CRITICALCVSS 9.4EG 9.42026-04-27
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not con…
- CVE-2026-3357HIGHCVSS 8.8EG 8.82026-04-08
IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
- CVE-2026-33701CRITICALCVSS 9.8EG 9.82026-03-27
OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data withou…
- CVE-2026-33728CRITICALCVSS 9.8EG 9.82026-03-27
dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JD…
- CVE-2026-33819CRITICALCVSS 10.0EG 10.02026-04-23
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
- CVE-2026-33858HIGHCVSS 8.8EG 8.82026-04-13
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. …
- CVE-2026-34084CRITICALCVSS 9.8EG 9.82026-05-05
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load(…
- CVE-2026-34202HIGHCVSS 7.5EG 7.52026-03-31
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (…
- CVE-2026-34615CRITICALCVSS 9.3EG 9.32026-04-14
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabili…
- CVE-2026-34659CRITICALCVSS 9.6EG 9.62026-05-12
Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul…
- CVE-2026-34838CRITICALCVSS 9.9EG 9.92026-04-02
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability in the AbstractSettingsCollection model leads to insecure deserialization when these settin…
- CVE-2026-34877CRITICALCVSS 9.8EG 9.82026-04-02
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corr…
- CVE-2026-34993HIGHCVSS 7.3EG 7.32026-06-02
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doin…
- CVE-2026-35171CRITICALCVSS 9.8EG 9.82026-04-06
Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation. The logging configuration s…
- CVE-2026-35300CRITICALCVSS 9.8EG 9.82026-06-17
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticat…
- CVE-2026-35337HIGHCVSS 8.8EG 8.82026-04-13
Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob usin…
- CVE-2026-35439HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-35464HIGHCVSS 7.5EG 7.52026-04-07
pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in t…
- CVE-2026-35537HIGHCVSS 7.5EG 7.52026-04-03
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
- CVE-2026-37552HIGHCVSS 8.4EG 8.42026-05-01
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(), then executes the result via call_user_…
- CVE-2026-37579HIGHCVSS 7.3EG 7.32026-05-28
An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component
- CVE-2026-38950HIGHCVSS 7.8EG 7.82026-06-01
An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from session directories using torch.load() with unrestricted deserialization.
- CVE-2026-39006CRITICALCVSS 9.8EG 9.82026-06-15
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
- CVE-2026-39253HIGHCVSS 8.1EG 8.12026-06-23
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.
- CVE-2026-39324CRITICALCVSS 9.8EG 9.82026-04-07
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls ba…
- CVE-2026-39434HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
- CVE-2026-39442HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
- CVE-2026-39443HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
- CVE-2026-39445HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
- CVE-2026-39446HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.
- CVE-2026-39467HIGHCVSS 7.2EG 7.22026-04-21
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.
- CVE-2026-39471HIGHCVSS 7.2EG 7.22026-06-15
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
- CVE-2026-39472HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
- CVE-2026-39474HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
- CVE-2026-39478HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
- CVE-2026-39481HIGHCVSS 7.2EG 7.22026-06-15
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
- CVE-2026-39498HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
- CVE-2026-39499HIGHCVSS 7.2EG 7.22026-06-15
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.
- CVE-2026-39529CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.
- CVE-2026-39532HIGHCVSS 8.8EG 8.82026-06-15
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
- CVE-2026-39539HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
- CVE-2026-39545HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
- CVE-2026-39550HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects Aperitif: from n/a through 1.6.
- CVE-2026-39551HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbel: from n/a through 1.8.1.
- CVE-2026-39554HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
- CVE-2026-39555HIGHCVSS 8.1EG 8.12026-06-02
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askka: from n/a through 1.3.1.
- CVE-2026-39556HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
- CVE-2026-39557HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →