CWE-502— Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.— MITRE CWE catalog
2,874 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-502page 54 of 58
- CVE-2026-39560HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
- CVE-2026-39567HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
- CVE-2026-39573HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
- CVE-2026-39576HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
- CVE-2026-39577MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Playroom <= 1.4.1 versions.
- CVE-2026-39578MEDIUMCVSS 5.5EG 5.52026-06-17
Unauthenticated PHP Object Injection in Valiance <= 1.2 versions.
- CVE-2026-39580HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
- CVE-2026-39832CRITICALCVSS 9.1EG 9.12026-05-22
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of t…
- CVE-2026-39890CRITICALCVSS 9.8EG 9.82026-04-08
PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an a…
- CVE-2026-40044CRITICALCVSS 9.8EG 9.82026-04-13
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cac…
- CVE-2026-40048HIGHCVSS 7.8EG 7.82026-04-27
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. The cas…
- CVE-2026-40357HIGHCVSS 8.8EG 8.82026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40368HIGHCVSS 8.0EG 8.02026-05-12
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40473HIGHCVSS 8.8EG 8.82026-04-27
The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a …
- CVE-2026-40725CRITICALCVSS 9.8EG 9.82026-06-17
Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.
- CVE-2026-40733HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
- CVE-2026-40735HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
- CVE-2026-40736HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
- CVE-2026-40738HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
- CVE-2026-40739HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
- CVE-2026-40751HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
- CVE-2026-40752HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
- CVE-2026-40753HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
- CVE-2026-40754HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
- CVE-2026-40755HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
- CVE-2026-40756HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
- CVE-2026-40757HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
- CVE-2026-40758HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
- CVE-2026-40759HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
- CVE-2026-40760HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
- CVE-2026-40761HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
- CVE-2026-40858HIGHCVSS 8.8EG 8.82026-04-27
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the…
- CVE-2026-40859HIGHCVSS 8.1EG 8.12026-07-06
Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, withou…
- CVE-2026-40860CRITICALCVSS 9.8EG 9.82026-04-27
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, …
- CVE-2026-40901HIGHCVSS 8.8EG 8.82026-04-16
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization gadget chain.…
- CVE-2026-40993HIGHCVSS 7.2EG 7.32026-06-10
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verifi…
- CVE-2026-41104CRITICALCVSS 7.5EG 10.02026-05-26
Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.
- CVE-2026-41316HIGHCVSS 8.1EG 8.12026-04-24
ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via…
- CVE-2026-41409CRITICALCVSS 9.8EG 9.82026-04-27
The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have b…
- CVE-2026-41486HIGHCVSS 8.8EG 8.82026-05-08
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_shaped_tensor) globally in PyArrow. When P…
- CVE-2026-41586CRITICALCVSS 9.3EG 9.32026-05-07
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call …
- CVE-2026-41635CRITICALCVSS 9.8EG 9.82026-04-27
Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The…
- CVE-2026-41699CRITICALCVSS 9.8EG 9.82026-06-11
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a pag…
- CVE-2026-41731HIGHCVSS 8.1EG 8.12026-06-10
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's defa…
- CVE-2026-41732HIGHCVSS 8.1EG 8.12026-06-10
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trus…
- CVE-2026-41855CRITICALCVSS 9.8EG 9.82026-06-09
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to una…
- CVE-2026-41862HIGHCVSS 8.8EG 8.82026-06-23
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remo…
- CVE-2026-41957HIGHCVSS 8.8EG 8.82026-05-13
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2026-42027CRITICALCVSS 9.8EG 9.82026-05-04
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description: The ExtensionLoader.instantiateExtension(Class, String) method lo…
- CVE-2026-42211HIGHCVSS 8.1EG 8.12026-06-02
React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the ap…
Map vulnerabilities like CWE-502 to your infrastructure
EchelonGraph correlates every CVE — across CWE-502 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →