Skip to main content

About CWE-502

Attackers can modify objects or data assumed to be protected, invoke unexpected functions, or force unbounded CPU use. Outcomes vary with the classes involved, and gadget chains can lead to unauthorized actions.

MITRE name
Deserialization of Untrusted Data
Abstraction
Base: abstract, but detailed enough to infer detection and prevention methods
Status
Draft
Also known as
Marshaling/Marshalling, Unmarshaling/Unmarshalling, Pickling, Unpickling, PHP Object Injection

Mitigations

  • Sign or seal serialized data, for example with an HMAC, so tampering is detected before deserialization.
  • Populate a new object from validated values rather than deserializing directly into live objects.
  • Mark sensitive fields as transient so they are not restored during deserialization.
  • Avoid making unnecessary types and gadgets available, and add only acceptable classes to an allowlist.
  • Use an application firewall as a temporary measure when the code cannot be fixed, noting that it might not cover all input vectors.

Detection
Automated static analysis (SAST) can find some instances and is rated highly effective by MITRE.

CWE-502 Vulnerabilities

37 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-50522
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft9.83.0%KEV2026-07-14
CVE-2026-58644
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft9.815.9%KEV2026-07-14
CVE-2026-45659
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft8.82.7%KEV2026-05-22
CVE-2026-12569
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
PTC9.346.0%KEV2026-06-18
CVE-2026-45247
Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
Mirasvit9.82.1%KEV2026-05-26
CVE-2023-21529
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft8.859.3%KEV2023-02-14
CVE-2026-20963
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft9.829.2%KEV2026-01-13
CVE-2025-26399
SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
SolarWinds9.889.5%KEV2025-09-23
CVE-2025-49113
RoundCube Webmail Deserialization of Untrusted Data Vulnerability
Roundcube9.999.0%KEV2025-06-02
CVE-2025-40551
SolarWinds Web Help Desk Deserialization of Untrusted Data Remote Code Execution Vulnerability
SolarWinds9.884.2%KEV2026-01-28
CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
Microsoft9.8100.0%KEV2025-10-14
CVE-2025-10035
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
Fortra10.099.8%KEV2025-09-18
CVE-2025-5086
Deserialization of Untrusted Data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
Dassault Systèmes9.096.9%KEV2025-06-02
CVE-2025-53690
Sitecore Products ViewState Deserialization Vulnerability
Sitecore9.051.1%KEV2025-09-03
CVE-2024-8069
Limited remote code execution with privilege of a NetworkService Account access
Citrix Session Recording5.114.6%KEV2024-11-12
CVE-2025-8875
Insecure Deserialization Vulnerability
N-able9.41.9%KEV2025-08-14
CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft9.8100.0%KEV2025-07-20
CVE-2025-24016
Remote code execution in Wazuh server
wazuh9.993.8%KEV2025-02-10
CVE-2025-3935
ScreenConnect Exposure to ASP.NET ViewState Code Injection
ConnectWise8.13.5%KEV2025-04-25
CVE-2025-42999
Insecure Deserialization in SAP NetWeaver (Visual Composer development server)
SAP_SE9.112.7%KEV2025-05-13
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Apache Software Foundation10.099.9%KEV2025-03-10
CVE-2025-0994
Trimble Cityworks Deserialization Vulnerability
Trimble8.631.1%KEV2025-02-06
CVE-2025-23006
SonicWall SMA1000 Appliances Deserialization Vulnerability
SonicWall9.823.4%KEV2025-01-23
CVE-2024-38094
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft7.250.9%KEV2024-07-09
CVE-2024-28986
SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability
SolarWinds9.884.6%KEV2024-08-13
CVE-2023-29300
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Adobe9.8100.0%KEV2023-07-12
CVE-2023-38203
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Adobe9.897.1%KEV2023-07-20
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
Apache Software Foundation10.099.9%KEV2023-10-27
CVE-2023-40044
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
Progress Software Corporation10.090.4%KEV2023-09-27
CVE-2023-26359
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Adobe9.817.0%KEV2023-03-23
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
x-stream8.598.1%KEV2021-08-23
CVE-2022-47986
IBM Aspera Faspex code execution
IBM9.8100.0%KEV2023-02-17
CVE-2023-0669
Fortra GoAnywhere MFT License Response Servlet Command Injection
Fortra7.2100.0%KEV2023-02-06
CVE-2019-15271
Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability
Cisco8.85.5%KEV2019-11-26
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Apache Software Foundation10.0100.0%KEV2021-12-10
CVE-2017-12149
Red Hat JBoss Application Server Remote Code Execution Vulnerability
Red Hat, Inc.9.890.7%KEV2017-10-04
CVE-2026-43825
Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel
Apache Software Foundation7.313.9%2026-07-06

Frequently Asked Questions

What is CWE-502?→

CWE-502 is the weakness of deserializing untrusted data without verifying that the result is valid. It is a Base-level entry in MITRE's catalog.

Is a class allowlist enough to stop deserialization attacks?→

MITRE says it helps but is not sufficient alone, because new gadgets keep being discovered. Signing serialized data and populating new objects from validated values are also recommended.

How many exploited vulnerabilities are classified as CWE-502?→

This database lists 37 CVE records mapped to CWE-502 by their CVE Numbering Authority. 36 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 17 to known ransomware campaigns. Examples include CVE-2026-50522, CVE-2026-58644, CVE-2026-45659.

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.