Threats Tagged 'cwe-502'
View all threats tagged with 'cwe-502'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-502'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-41699: CWE-502: Deserialization of Untrusted Data in Spring Spring for GraphQLCVE-2026-41699 0 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8. Join the discussion | CVE Database V5 | 06/11/2026, 05:04:43 UTC Added: 06/11/2026, 06:46:22 UTC |
CVE-2026-11815: CWE-502 Deserialization of untrusted data in Broadcom Layer 7 API GatewayCVE-2026-11815 0 An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution. Join the discussion | CVE Database V5 | 06/10/2026, 06:39:26 UTC Added: 06/10/2026, 06:41:08 UTC |
CVE-2026-41732: CWE-502: Deserialization of Untrusted Data in Spring Spring for Apache PulsarCVE-2026-41732 0 JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a safe default allow-list. Affected versions: Spring for Apache Pulsar 2.0.0 through 2.0.5; 1.2.0 through 1.2.17; 1.1.0 through 1.1.17. Join the discussion | CVE Database V5 | 06/09/2026, 23:49:31 UTC Added: 06/09/2026, 23:55:53 UTC |
CVE-2026-41731: CWE-502: Deserialization of Untrusted Data in Spring Spring for Apache KafkaCVE-2026-41731 0 JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11. Join the discussion | CVE Database V5 | 06/09/2026, 23:49:26 UTC Added: 06/09/2026, 23:55:53 UTC |
CVE-2026-40993: CWE-502: Deserialization of Untrusted Data in Spring Spring SecurityCVE-2026-40993 0 An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the columns containing the collection of verification or encryption credentials (verification_credentials and encryption_credentials, respectively). Affected versions: Spring Security 7.0.0 through 7.0.5. Join the discussion | CVE Database V5 | 06/09/2026, 23:46:39 UTC Added: 06/09/2026, 23:55:46 UTC |
CVE-2026-44963: CWE-502 Deserialization of Untrusted Data in Veeam Backup and ReplicationCVE-2026-44963 0 A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. Join the discussion | CVE Database V5 | 06/09/2026, 22:27:01 UTC Added: 06/09/2026, 22:55:45 UTC |
CVE-2026-48560: CWE-502: Deserialization of Untrusted Data in Microsoft Microsoft SharePoint Enterprise Server 2016CVE-2026-48560 0 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Join the discussion | CVE Database V5 | 06/09/2026, 17:05:51 UTC Added: 06/09/2026, 17:27:43 UTC |
CVE-2026-45484: CWE-502: Deserialization of Untrusted Data in Microsoft Microsoft SharePoint Enterprise Server 2016CVE-2026-45484 0 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 06/09/2026, 17:05:50 UTC Added: 06/09/2026, 17:26:52 UTC |
CVE-2026-26142: CWE-502: Deserialization of Untrusted Data in Microsoft Nuance PowerScribe 360 4.0CVE-2026-26142 0 Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. Join the discussion | CVE Database V5 | 06/09/2026, 17:05:17 UTC Added: 06/09/2026, 17:26:15 UTC |
CVE-2026-49740: CWE-502 Deserialization of Untrusted Data in TYPO3 TYPO3 CMSCVE-2026-49740 0 TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without integrity validation or class restrictions. An attacker with write access to the underlying storage backend (cache store or sys_registry database table) could inject a crafted serialized payload to trigger PHP Object Injection, potentially exploiting a gadget chain to achieve Remote Code Execution or other high-impact effects. Exploiting this vulnerability requires direct local write access to the storage, such as the SQL database or file system. This issue affects TYPO3 CMS versions before 10.4.57, 11.0.0-11.5.51, 12.0.0-12.4.46, 13.0.0-13.4.31 and 14.0.0-14.3.3. Join the discussion | CVE Database V5 | 06/09/2026, 10:53:55 UTC Added: 06/09/2026, 11:25:53 UTC |
Showing 1 to 10 of 604 results