Deserialization of Untrusted Data (CWE-502)
CWE-502 occurs when a product deserializes untrusted data without making sure the resulting data is valid. Serialized objects can carry state or trigger methods the developer never intended to run. MITRE lists marshaling, unmarshaling and pickling as alternate terms for the same process.
About CWE-502
Attackers can modify objects or data assumed to be protected, invoke unexpected functions, or force unbounded CPU use. Outcomes vary with the classes involved, and gadget chains can lead to unauthorized actions.
Mitigations
- Sign or seal serialized data, for example with an HMAC, so tampering is detected before deserialization.
- Populate a new object from validated values rather than deserializing directly into live objects.
- Mark sensitive fields as transient so they are not restored during deserialization.
- Avoid making unnecessary types and gadgets available, and add only acceptable classes to an allowlist.
- Use an application firewall as a temporary measure when the code cannot be fixed, noting that it might not cover all input vectors.
Detection
Automated static analysis (SAST) can find some instances and is rated highly effective by MITRE.
CWE-502 Vulnerabilities
37 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 3.0% | KEV | 2026-07-14 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 15.9% | KEV | 2026-07-14 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 8.8 | 2.7% | KEV | 2026-05-22 |
| CVE-2026-12569 | Remote Code Execution (RCE) vulnerability in Windchill PDMlink | PTC | 9.3 | 46.0% | KEV | 2026-06-18 |
| CVE-2026-45247 | Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection | Mirasvit | 9.8 | 2.1% | KEV | 2026-05-26 |
| CVE-2023-21529 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 59.3% | KEV | 2023-02-14 |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 29.2% | KEV | 2026-01-13 |
| CVE-2025-26399 | SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability | SolarWinds | 9.8 | 89.5% | KEV | 2025-09-23 |
| CVE-2025-49113 | RoundCube Webmail Deserialization of Untrusted Data Vulnerability | Roundcube | 9.9 | 99.0% | KEV | 2025-06-02 |
| CVE-2025-40551 | SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability | SolarWinds | 9.8 | 84.2% | KEV | 2026-01-28 |
| CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2025-10-14 |
| CVE-2025-10035 | Deserialization Vulnerability in GoAnywhere MFT's License Servlet | Fortra | 10.0 | 99.8% | KEV | 2025-09-18 |
| CVE-2025-5086 | Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 | Dassault Systèmes | 9.0 | 96.9% | KEV | 2025-06-02 |
| CVE-2025-53690 | Sitecore Products ViewState Deserialization Vulnerability | Sitecore | 9.0 | 51.1% | KEV | 2025-09-03 |
| CVE-2024-8069 | Limited remote code execution with privilege of a NetworkService Account access | Citrix Session Recording | 5.1 | 14.6% | KEV | 2024-11-12 |
| CVE-2025-8875 | Insecure Deserialization Vulnerability | N-able | 9.4 | 1.9% | KEV | 2025-08-14 |
| CVE-2025-53770 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2025-07-20 |
| CVE-2025-24016 | Remote code execution in Wazuh server | wazuh | 9.9 | 93.8% | KEV | 2025-02-10 |
| CVE-2025-3935 | ScreenConnect Exposure to ASP.NET ViewState Code Injection | ConnectWise | 8.1 | 3.5% | KEV | 2025-04-25 |
| CVE-2025-42999 | Insecure Deserialization in SAP NetWeaver (Visual Composer development server) | SAP_SE | 9.1 | 12.7% | KEV | 2025-05-13 |
| CVE-2025-24813 | Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT | Apache Software Foundation | 10.0 | 99.9% | KEV | 2025-03-10 |
| CVE-2025-0994 | Trimble Cityworks Deserialization Vulnerability | Trimble | 8.6 | 31.1% | KEV | 2025-02-06 |
| CVE-2025-23006 | SonicWall SMA1000 Appliances Deserialization Vulnerability | SonicWall | 9.8 | 23.4% | KEV | 2025-01-23 |
| CVE-2024-38094 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 7.2 | 50.9% | KEV | 2024-07-09 |
| CVE-2024-28986 | SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability | SolarWinds | 9.8 | 84.6% | KEV | 2024-08-13 |
| CVE-2023-29300 | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution | Adobe | 9.8 | 100.0% | KEV | 2023-07-12 |
| CVE-2023-38203 | Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE | Adobe | 9.8 | 97.1% | KEV | 2023-07-20 |
| CVE-2023-46604 | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack | Apache Software Foundation | 10.0 | 99.9% | KEV | 2023-10-27 |
| CVE-2023-40044 | WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability | Progress Software Corporation | 10.0 | 90.4% | KEV | 2023-09-27 |
| CVE-2023-26359 | Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution | Adobe | 9.8 | 17.0% | KEV | 2023-03-23 |
| CVE-2021-39144 | XStream is vulnerable to a Remote Command Execution attack | x-stream | 8.5 | 98.1% | KEV | 2021-08-23 |
| CVE-2022-47986 | IBM Aspera Faspex code execution | IBM | 9.8 | 100.0% | KEV | 2023-02-17 |
| CVE-2023-0669 | Fortra GoAnywhere MFT License Response Servlet Command Injection | Fortra | 7.2 | 100.0% | KEV | 2023-02-06 |
| CVE-2019-15271 | Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability | Cisco | 8.8 | 5.5% | KEV | 2019-11-26 |
| CVE-2021-44228 | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | Apache Software Foundation | 10.0 | 100.0% | KEV | 2021-12-10 |
| CVE-2017-12149 | Red Hat JBoss Application Server Remote Code Execution Vulnerability | Red Hat, Inc. | 9.8 | 90.7% | KEV | 2017-10-04 |
| CVE-2026-43825 | Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel | Apache Software Foundation | 7.3 | 13.9% | 2026-07-06 |
Frequently Asked Questions
What is CWE-502?→
CWE-502 is the weakness of deserializing untrusted data without verifying that the result is valid. It is a Base-level entry in MITRE's catalog.
Is a class allowlist enough to stop deserialization attacks?→
MITRE says it helps but is not sufficient alone, because new gadgets keep being discovered. Signing serialized data and populating new objects from validated values are also recommended.
How many exploited vulnerabilities are classified as CWE-502?→
This database lists 37 CVE records mapped to CWE-502 by their CVE Numbering Authority. 36 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 17 to known ransomware campaigns. Examples include CVE-2026-50522, CVE-2026-58644, CVE-2026-45659.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.