CWE-502

Medium likelihood

Deserialization of Untrusted Data

Parent: CWE-913 - Improper Control of Dynamically-Managed Code Resources

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

2,741 vulnerabilities with CWE-502
CVE-2026-31253 HIGH
flash-attention thru e724e2588c - Deserialization
CVSS 7.3
CVE-2026-31250 HIGH
CosyVoice - Remote Code Execution via Insecure PyTorch Checkpoint Deserialization
CVSS 7.3
CVE-2026-31249 HIGH
CosyVoice - Insecure Deserialization
CVSS 7.3
CVE-2026-7818 HIGH
pgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code execution
CVSS 7.0
CVE-2026-41486 HIGH
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVSS 8.8
CVE-2026-44126 CRITICAL
SEPPmail Secure Email Gateway - Insecure Deserialization
CVE-2026-5127 HIGH
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object Injection
CVSS 8.8
CVE-2026-41586 CRITICAL
Hyperledger Fabric 1.0.0-2.2.26 fabric-sdk-java - Java Deserialization Remote Code Execution
CVE-2026-34084 CRITICAL
PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load
CVSS 9.8
CVE-2026-7712 MEDIUM
MindsDB Pickle pickle.loads deserialization
CVSS 6.3
CVE-2026-7647 HIGH
Profile Builder Pro <= 3.14.5 - Unauthenticated PHP Object Injection
CVSS 8.1
CVE-2026-7597 MEDIUM
mem0ai mem0 faiss.py pickle.dump deserialization
CVSS 6.3
CVE-2026-42473 CRITICAL
MixPHP Framework 2.x-2.2.17 - Deserialization
CVSS 9.8
CVE-2026-42472 CRITICAL
MixPHP Framework 2.x-2.2.17 - Deserialization
CVSS 9.8
CVE-2026-42471 HIGH
MixPHP Framework 2.x-2.2.17 - Deserialization
CVSS 8.1
CVE-2026-37552 HIGH
MixPHP Framework 2.x-2.2.17 - Deserialization
CVSS 8.4
CVE-2026-42779 CRITICAL
Apache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCE (take 2)
CVSS 9.8
CVE-2026-42778 CRITICAL
Apache MINA: CWE-502 Deserialization of Untrusted Data (take 2)
CVSS 9.8
CVE-2026-7584 HIGH
Arbitrary Code Execution via Unsafe Deserialization in LabOne Q
CVSS 7.8
CVE-2026-42521 MEDIUM
Jenkins Project Jenkins Matrix Authorization Strategy Plugin < 3.2.9 - Information Disclosure
CVSS 6.5
CVE-2026-7317 MEDIUM
Grav CMS Cache Value FileCache.php doGet deserialization
CVSS 5.0
CVE-2026-24186 HIGH
NVIDIA FLARE SDK <2.7.2 - Deserialization
CVSS 8.8
CVE-2026-27172 HIGH
Apache Camel: Unsafe Java deserialization in camel-consul ConsulRegistry allows arbitrary code execution via malicious values read from the Consul KV store
CVSS 8.8
CVE-2026-41409 CRITICAL
Apache MINA: CWE-502 Deserialization of Untrusted Data
CVSS 9.8
CVE-2026-40858 HIGH
Apache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation Repository
CVSS 8.8
Details
Vulnerabilities 2,741
Exploit Likelihood Medium