Skip to content
Noroxi

CWE-502 · 3,045 records

Deserialization of untrusted data

Why does it happen?

Data received over the network is deserialized into the language’s native object format without verifying its source. Code paths inside the object can be triggered during deserialization.

Vulnerable and fixed code

A representative teaching example. Highlighted lines mark where the bug and the fix are.

Vulnerable

python
payload = sock.recv(65536)job = pickle.loads(payload)

Fixed

python
payload = sock.recv(65536)if not hmac.compare_digest(sign(payload), header_sig):    raise PermissionError("invalid signature")job = JobSchema.validate(json.loads(payload))

How to prevent it

  1. 01Use data-only formats (such as JSON) for network messages.
  2. 02Verify the message source with a signature or mutual TLS.
  3. 03Validate deserialized data against a schema.

CVEs in this class

3,045 records

  • A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    facebook · reactDec 3, 2025

  • ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pages.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    forgerock · access managementJul 22, 2021

  • Microsoft SharePoint Server Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · sharepoint serverJul 19, 2025

  • Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · coldfusionJul 12, 2023

  • Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · windows server 2012Oct 14, 2025

  • IBM Aspera Faspex code execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ibm · aspera faspexFeb 17, 2023

  • Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components).

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    oracle · weblogic serverApr 18, 2018

  • Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    zohocorp · manageengine desktop centralMar 6, 2020

  • Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    zohocorp · manageengine access manager plusJul 19, 2022

  • Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web ser

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    liferay · liferay portalMar 20, 2020

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · activemqOct 27, 2023

  • Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    telerik · ui for asp.net ajaxDec 11, 2019

  • Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    jenkins · jenkinsJan 29, 2018

  • A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/cor

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    jenkins · jenkinsDec 10, 2018

  • Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allo

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    ibm · sterling b2b integratorJan 2, 2016

  • Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achi

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    sitecore · experience platformNov 5, 2021

  • Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation).

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    oracle · access managerJan 15, 2020

  • Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    adobe · coldfusionJul 20, 2023

  • The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary

    CriticalCVSS 9.8KEVWeaponizedEPSS 96%

    oracle · virtual desktop infrastructureNov 18, 2015

  • An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    kentico · xperienceMar 26, 2019

  • Remote code execution in Wazuh server

    CriticalCVSS 9.9KEVWeaponizedEPSS 94%

    wazuh · wazuhFeb 10, 2025

  • In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn

    CriticalCVSS 9.8KEVWeaponizedEPSS 91%

    redhat · jboss enterprise application platformOct 4, 2017

  • Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserializa

    CriticalCVSS 9.8KEVWeaponizedEPSS 91%

    adobe · coldfusionApr 27, 2017

  • A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    veeam · veeam backup \& replicationSep 7, 2024

  • In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    jetbrains · teamcityJul 27, 2026

All vulnerability classes