Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 555— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Premium intel
CVSS 8.4
llama-index 0.11.16 Arbitrary Code Execution via Pickle Deserialization
huntr.com · 2026-01-20

--- ### Vulnerability Overview - **Vulnerability Type**: CWE-434: Arbitrary File Upload with Dangerous Type - **Severity**: High (8.8) - **Attack Vector**: Network - **Attack Complexity**: Low - **Req…

Read more
Premium intel
CVSS 10.0
Fastjson 1.2.47 Deserialization RCE Vulnerability Reproduction and Exploitation Analysis
github.com · 2026-01-20

### Vulnerability Key Information #### Vulnerability Description - **Vulnerability Type**: Fastjson 1.2.47 Deserialization Remote Code Execution (RCE) - **Affected Versions**: Fastjson 1.2.47 and earl…

Read more
Python Pickle Deserialization RCE via ctypes/pydoc Gadget Chain Bypass
github.com · 2026-01-20

From the screenshot, the following key information about the vulnerability can be extracted: ### Summary - **Vulnerability Name**: `ctypes and pydoc gadget chain to bypass detection` - **Publisher**: …

Read more
TYPO3 FileSpool Deserialization Hardening (CVE-2026-0859)
github.com · 2026-01-20

### Key Information **1. Vulnerability Type** ``` [SECURITY] Hardening message deserialization in FileSpool transport ``` **2. Vulnerability Description** - **Issue**: Serialized messages using the de…

Read more
GPT Academic CVE-2026-0762 Deserialization RCE via stream_daas
www.zerodayinitiative.com · 2026-01-27

- **CVE ID**: CVE-2026-0762 - **CVSS Score**: 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) - **Affected Vendor**: GPT Academic - **Affected Product**: GPT Academic - **Vulnerability Details**: - This vul…

Read more
Langflow Deserialization RCE Vulnerability (CVE-2026-0772) Advisory
www.zerodayinitiative.com · 2026-01-27

### Critical Vulnerability Information - **CVE ID**: CVE-2026-0772 - **CVSS Score**: 7.5, AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - **Affected Vendors**: Langflow - **Affected Products**: Langflow - **Vul…

Read more
GPT Academic CVE-2026-0764 Pre-Auth RCE via Untrusted Data Deserialization in Upload Endpoint
www.zerodayinitiative.com · 2026-01-27

### Key Information - **CVE ID**: CVE-2026-0764 - **CVSS Score**: 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - **Affected Vendors**: GPT Academic - **Affected Products**: GPT Academic - **Vulnerability …

Read more
Anritsu ShockLine CHX File Parsing Deserialization RCE (CVE-2025-15348)
www.zerodayinitiative.com · 2026-01-27

### Vulnerability Key Information #### Basic Information - **Date**: December 30th, 2025 - **Title**: (0Day) Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution …

Read more
CVSS 8.1
NXT Plugin Fix: Unauthorized Access and PHP Deserialization Vulnerability
plugins.trac.wordpress.org · 2026-01-27

### Key Information 1. **Enhanced Security Measures** - Removed `wp_ajax_nopriv_*` actions that could be triggered by unauthenticated users, to prevent security risks caused by unauthorized access. 2.…

Read more
Apache Karaf Decanter log-socket Deserialization Vulnerability (CVE-2026-24656)
lists.apache.org · 2026-01-27

**CVE-2026-24656: Apache Karaf: Decanter log-socket collector has deserialization vulnerability** - **Severity:** important - **Affected versions:** - Apache Karaf (org.apache.karaf.decanter.collector…

Read more
Premium intel
CVSS 6.8
Tendenci Helpdesk Insecure Deserialization Vulnerability (CVE-2026-23946) Analysis
github.com · 2026-01-27

### Key Information #### Vulnerability Overview - **Vulnerability Name**: Deserialization vulnerability in Tendenci Helpdesk module - **CVE ID**: CVE-2026-23946 - **GitHub Advisory ID**: GHSA-339m-4qw…

Read more
Premium intel
CVSS 9.8
Laravel Reverb <1.7.0 Insecure Deserialization RCE Vulnerability
github.com · 2026-01-27

### Vulnerability Key Information #### Vulnerability Description - **Vulnerability Type**: Insecure Deserialization (CWE-502) - **Severity**: Critical (9.8) - **Impact**: Affects Laravel Reverb versio…

Read more
PLY CVE-2025-56005: Untrusted Data Deserialization RCE
github.com · 2026-01-27

### Critical Vulnerability Information - **Vulnerability Name**: Undocumented Remote Code Execution in PLY - **CVE ID**: CVE-2025-56005 - **Reporter**: Ahmed Abd - **Disclosure Date**: July 1, 2025 - …

Read more
Premium intel
CVSS 6.8
Tendenci Unrestricted Deserialization Vulnerability (CVE-2020-14942) Advisory
github.com · 2026-01-27

### Critical Vulnerability Information - **Vulnerability ID**: CVE-2020-14942 - **CVSS Score**: 9.3/10 (Critical Severity) - **Affected Versions**: - Tendenci Repository Issue: - GitHub Security Advis…

Read more
Premium intel
CVSS 7.8
PHPUnit CVE-2026-24765 Unsafe Deserialization in PHPT Cleanup
github.com · 2026-01-28

From the webpage screenshot, the following key vulnerability information can be obtained: ### Vulnerability Overview - **Vulnerability Type**: Insecure Deserialization (CWE-502) - **Affected Component…

Read more
CVSS 6.3
bolo-solo v2.6.4 SnakeYAML Deserialization RCE in import/markdown
github.com · 2026-01-31

### Vulnerability Key Information #### Vulnerability Description In the stable version bolo-solo v2.6.4, there is a deserialization vulnerability in the "import/markdown" path, caused by unsafe YAML l…

Read more
pdfminer.six CMap Loader Unsafe Deserialization via Pickle (CVE-2025-64512)
github.com · 2026-02-04

## Vulnerability Key Information ### Vulnerability Overview - **CVE ID**: CVE-2025-64512 - **CVSS v3 Score**: 8.3/10 - **Severity**: High ### Vulnerability Details - **Component**: pdfminer.six CMap l…

Read more
Premium intel
CVSS 9.8
Jinja2 Java BeanELResolver Security Fix: Preventing Illegal Access and Code Injection
github.com · 2026-02-05

### Key Information: - **Code Change Report**: This commit modifies the file `Jinja2BeanELResolverTest.java` located under the `el/ext` module of the `Jinja2` template engine. - **Changes Made**: The …

Read more
CVSS 7.3
CVE-2026-2113: tpadmin WebUploader Deserialization Vulnerability
vuldb.com · 2026-02-08

## Vulnerability Key Information - **Vulnerability Identifier:** - VDB-344688 - CVE-2026-2113 - GCVE-100-344688 - **Vulnerability Summary:** - A critical vulnerability has been discovered in yuan1994 …

Read more
Premium intel
CVSS 7.8
PowerDocu.Common Insecure Deserialization RCE Vulnerability
github.com · 2026-02-10

## Key Information ### Vulnerability Description - **Type:** Remote Code Execution (RCE) via unsafe deserialization - **Affected Package:** PowerDocu.Common (NuGet) - **Affected Versions:** (flowJSON,…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.