CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,987 vulnerabilities with CWE-502
CVE-2026-10566 MEDIUM
FoundationAgents MetaGPT schema.py Message.check_instruct_content deserialization
CVSS 5.3
CVE-2026-9330 HIGH
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via SAML Web SSO Deserialization
CVSS 8.5
CVE-2026-9319 CRITICAL
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via JAX-WS Endpoint Deserialization
CVSS 9.0
CVE-2026-49121 HIGH
AI Tensor Engine for ROCm (AITER) <= 0.1.14 - Remote Code Execution via Pickle Deserialization
CVSS 8.1
CVE-2026-38950 HIGH
ESA AnomalyMatch < 1.3.1 - Remote Code Execution via Unsafe Model Checkpoint Deserialization
CVSS 7.8
CVE-2026-10532 LOW
Logback deserialization whitelist bypass for Proxy objects
CVE-2026-7858 CRITICAL
Dassault Teamwork Cloud and Magic Collaboration Studio - Deserialization RCE
CVSS 9.8
CVE-2026-45360 HIGH
Apache Airflow: Arbitrary import in custom deadline-reference deserialization
CVSS 7.3
CVE-2026-42359 HIGH
Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator
CVSS 8.8
CVE-2026-10042 CRITICAL
manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model
CVSS 9.8
CVE-2026-9828 LOW
Logback deserialization whitelist bypass for java.lang and java.util
CVE-2026-37579 HIGH
SMSGate sms-core <= 2.1.13.6 - Remote Code Execution via Cmpp7FDeliverRequestMessageCodec
CVSS 7.3
CVE-2026-47161 HIGH
RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle Deserialization
CVE-2026-45134 HIGH
LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVSS 7.1
CVE-2026-48919 MEDIUM
Jenkins Active Directory Plugin < 2.41 - Deserialization of Untrusted Data
CVSS 6.6
CVE-2026-48917 MEDIUM
Jenkins LDAP Plugin < 807.v7d7de30930cf - Deserialization of Untrusted Data from LDAP Referrals
CVSS 6.6
CVE-2026-44843 HIGH
LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists
CVSS 8.2
CVE-2026-24162 HIGH
Nvidia Merlin Transformers4Rec - Deserialization of Untrusted Data
CVSS 7.8
CVE-2026-45247 CRITICAL KEV
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
CVSS 9.8
CVE-2026-9497 MEDIUM
changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserialization
CVSS 6.3
CVE-2026-4372 HIGH
Arbitrary Remote Code Execution via `_attn_implementation_internal` Config Injection in huggingface/transformers
CVSS 7.8
CVE-2026-45659 HIGH KEV
Microsoft SharePoint Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-41104 CRITICAL
Microsoft Planetary Computer Pro Information Disclosure Vulnerability
CVSS 10.0
CVE-2026-9291 HIGH
Insecure Deserialization in Amazon Braket SDK Job Results Processing
CVSS 7.1
CVE-2026-39832 CRITICAL
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
CVSS 9.1
Details
Vulnerabilities 2,987
Exploit Likelihood Medium