Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 553— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Premium intel
CVSS 8.0
PHP Deserialization Hardening: allowed_classes Patch Analysis
github.com · 2026-07-18

### Vulnerability Overview This vulnerability relates to the hardening of deserialization functionality and the refinement of allowed classes. Specifically, it includes: - Using safer alternatives for…

Read more
APScheduler JSONSerializer Deserialization RCE (CVE-2026-31072)
gist.github.com · 2026-05-22

# APScheduler JSONSerializer Deserialization Remote Code Execution Vulnerability (CVE-2026-31072) ## Vulnerability Overview APScheduler's `JSONSerializer` (and `CBORSerializer`), although documented a…

Read more
CVSS 7.3
Boost Serialization Unsafe Deserialization Vulnerability and PoC
gist.github.com · 2026-06-13

### Vulnerability Overview In Boost Serialization versions v1.89.0 and earlier, there is an insecure deserialization issue. Under specific conditions, unvalidated input can lead to type confusion and …

Read more
MixPHP 2.x Deserialization RCE and SQL Injection (CVE-2026-37552, CVE-2026-42471 through 42475) · GitHub
gist.github.com · 2026-05-02

# MixPHP Framework Deserialization RCE and SQL Injection Vulnerability Summary ## Vulnerability Overview The MixPHP framework contains multiple critical security vulnerabilities, including Remote Code…

Read more
Premium intel
CVSS 7.2
Fix: Remote Code Execution via Jinacore Deserialization in OkAuth
github.com · 2026-04-02

### Vulnerability Summary **Vulnerability Overview** * **Vulnerability Type**: Remote Code Execution (RCE) * **Root Cause**: Deserialization vulnerability in the `Jinacore` component within `OkAuth`. …

Read more
CVSS 3.1
Roundcube Fix Unsafe Deserialization Arbitrary File Write and INP Injection
github.com · 2026-04-03

### Vulnerability Overview This update addresses two critical security vulnerabilities: 1. **INP Injection and CRLF Bypass**: A vulnerability exists in the mail search functionality, allowing INP inje…

Read more
Fastjson Deserialization Vulnerability Analysis and RCE PoC Code
xz.aliyun.com · 2026-07-05

### Vulnerability Overview This webpage introduces the `ezfastjson` Java project, which involves an analysis of vulnerabilities in Fastjson deserialization. Fastjson is a commonly used Java JSON libra…

Read more
Premium intel
CVSS 8.8
Pimcore Dashboard Deserialization Fix via allowed_classes
github.com · 2026-08-13

### Vulnerability Overview The vulnerability stems from the use of `unserialize()` without the `allowed_classes` option, leading to potential security risks. Specifically, during the loading of Dashbo…

Read more
CVSS 6.4
Apache ActiveMQ CVE-2023-46604 Remote Code Execution Vulnerability Analysis and Mitigation
www.wordfence.com · 2026-05-22

# Vulnerability Summary ## Vulnerability Overview * **Vulnerability Name**: Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2023-46604) * **Vulnerability Type**: Remote Code Execution (RCE) *…

Read more
Premium intel
CVSS 3.7
Roundcube: Fix Arbitrary File Write via Unsafe Deserialization in redis/newcache Session Handler
github.com · 2026-04-03

### Vulnerability Overview This screenshot presents a security fix commit (Commit 44e4d99) in the Roundcube email client. It addresses an **arbitrary file write vulnerability** caused by **unsafe dese…

Read more
CVE-502: RCE via Unsafe Pickle Deserialization in Async Inference Pipeline
github.com · 2026-04-24

# Vulnerability Summary ## Overview - **Vulnerability ID**: CVE-502 (Deserialization of Untrusted Data) - **Description**: In the asynchronous inference pipeline, there exist unsafe calls to `pickle.l…

Read more
ZI-SA-2026-002: Arbitrary Code Execution via Unsafe Deserialization in LabOne Q | Zurich Instruments
www.zhinst.com · 2026-05-01

# Summary of Deserialization Vulnerability in Zurich Instruments LabOne Q ## Vulnerability Overview * **Vulnerability ID**: ZI-SA-2026-002 * **Vulnerability Type**: Unsafe Deserialization * **CVSS Sco…

Read more
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditi
github.com · 2026-06-13

### Vulnerability Overview The `FileSystemTicketStore` in the SimpleSAMLphp `casserver` module contains a path traversal vulnerability, allowing remote attackers to read, deserialize, and delete targe…

Read more
Ray CVE-2024-2056 RCE via Parquet Cloudpickle Deserialization
github.com · 2026-05-09

### Vulnerability Overview A critical security vulnerability (CVE-2024-2056) has been identified in the Ray project, allowing attackers to execute arbitrary code through crafted Parquet files. This vu…

Read more
mchange-commons-java prior to v0.6.0 contains elements susceptible to abuse via JNDI injection and "deserialization gadg
github.com · 2026-07-02

### Vulnerability Overview `mchange-commons-java` versions prior to 0.6.0 are vulnerable to JNDI injection and deserialization gadgets. Attackers can construct malicious JNDI reference objects to exec…

Read more
RCE in langgraph-checkpoint JsonPlusSerializer via Unsafe Deserialization
github.com · 2025-11-09

## Vulnerability Overview ### Vulnerability Name RCE in "json" mode of JsonPlusSerializer ### Affected Versions langgraph-checkpoint 3.0 ### Vulnerability Description Prior to version 3.0, JsonPlusSer…

Read more
Premium intel
CVSS 8.2
CVE-2024-4843 LangChain Unsafe Deserialization Vulnerability Advisory
github.com · 2026-05-27

### Vulnerability Overview **Vulnerability Name**: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlist **CVE ID**: CVE-2024-4843 **CVSS v3 base metr…

Read more
bitsery/CHANGELOG.md at master · fraillt/bitsery · GitHub
github.com · 2026-05-26

### Vulnerability Overview In version 5.2.5 (2025-10-09), a security vulnerability was identified. This vulnerability involves a security issue during the deserialization process, specifically: a craf…

Read more
RCE via Unsafe Deserialization in jsonpickle.loads
huntr.com · 2025-07-12

## Critical Vulnerability Information ### Vulnerability Description - **Type**: Unsafe Deserialization (`jsonpickle.loads`) - **Impact**: Remote Code Execution (RCE) - **Cause**: The `jsonpickle.loads…

Read more
gleam-lang: Fix toml deserialization validation bypass allowing config tampering
github.com · 2026-06-02

### Vulnerability Overview This vulnerability involves a security issue in the `toml` deserialization process within the `gleam-lang/gleam` project. Specifically, it manifests as a lack of strict vali…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.