CWE-502
Medium likelihoodDeserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
2,987 vulnerabilities with CWE-502
CVE-2026-10566
MEDIUM
FoundationAgents MetaGPT schema.py Message.check_instruct_content deserialization
CVSS 5.3
CVE-2026-9330
HIGH
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via SAML Web SSO Deserialization
CVSS 8.5
CVE-2026-9319
CRITICAL
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via JAX-WS Endpoint Deserialization
CVSS 9.0
CVE-2026-49121
HIGH
AI Tensor Engine for ROCm (AITER) <= 0.1.14 - Remote Code Execution via Pickle Deserialization
CVSS 8.1
CVE-2026-38950
HIGH
ESA AnomalyMatch < 1.3.1 - Remote Code Execution via Unsafe Model Checkpoint Deserialization
CVSS 7.8
CVE-2026-10532
LOW
Logback deserialization whitelist bypass for Proxy objects
CVE-2026-7858
CRITICAL
Dassault Teamwork Cloud and Magic Collaboration Studio - Deserialization RCE
CVSS 9.8
CVE-2026-45360
HIGH
Apache Airflow: Arbitrary import in custom deadline-reference deserialization
CVSS 7.3
CVE-2026-42359
HIGH
Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
CVSS 8.8
CVE-2026-10042
CRITICAL
manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model
CVSS 9.8
CVE-2026-9828
LOW
Logback deserialization whitelist bypass for java.lang and java.util
CVE-2026-37579
HIGH
SMSGate sms-core <= 2.1.13.6 - Remote Code Execution via Cmpp7FDeliverRequestMessageCodec
CVSS 7.3
CVE-2026-47161
HIGH
RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle Deserialization
CVE-2026-45134
HIGH
LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVSS 7.1
CVE-2026-48919
MEDIUM
Jenkins Active Directory Plugin < 2.41 - Deserialization of Untrusted Data
CVSS 6.6
CVE-2026-48917
MEDIUM
Jenkins LDAP Plugin < 807.v7d7de30930cf - Deserialization of Untrusted Data from LDAP Referrals
CVSS 6.6
CVE-2026-44843
HIGH
LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists
CVSS 8.2
CVE-2026-24162
HIGH
Nvidia Merlin Transformers4Rec - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-45247
CRITICAL
KEV
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
CVSS 9.8
CVE-2026-9497
MEDIUM
changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserialization
CVSS 6.3
CVE-2026-4372
HIGH
Arbitrary Remote Code Execution via `_attn_implementation_internal` Config Injection in huggingface/transformers
CVSS 7.8
CVE-2026-45659
HIGH
KEV
Microsoft SharePoint Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-41104
CRITICAL
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
CVSS 10.0
CVE-2026-9291
HIGH
Insecure Deserialization in Amazon Braket SDK Job Results Processing
CVSS 7.1
CVE-2026-39832
CRITICAL
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVSS 9.1
Details
Vulnerabilities
2,987
Exploit Likelihood
Medium