MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deseria
IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human language
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, a
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue af
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experim
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter
A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonR
A weakness has been identified in FedML-AI FedML up to 0.8.9. Affected is the function sendMessage of the file grpc_serv
NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exp
LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera
The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an ins
A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in t
An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMe
Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin
Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFrom
Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document c
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of
A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of th
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Obj
Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This iss
Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a
Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to
Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the '
Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to P
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.Th
Frequently Asked Questions
What is CWE-502?
CWE-502 (Deserialization of Untrusted Data) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-502?
There are 3,680 CVE records associated with CWE-502 in our database. Of these, 1189 are critical severity, 1464 are high severity, and 360 are medium severity.
How can I protect against CWE-502 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-502 using AI-powered security agents.
Detect CWE-502 Vulnerabilities
CyberStrike's AI agents automatically detect deserialization of untrusted data vulnerabilities across your infrastructure.
Get Started