Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 560— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Security Bulletin: IBM WebSphere eXtreme Scale is affected by Insecure Deserilization
www.ibm.com · 2026-07-04

# IBM WebSphere eXtreme Scale Deserialization Vulnerability ## Vulnerability Overview IBM WebSphere eXtreme Scale contains an insecure deserialization vulnerability (CVE-2026-13759). This vulnerabilit…

Read more
Fix unsafe unserialization · PrestaShop/ps_facetedsearch@9ca839f · GitHub
github.com · 2026-07-18

### Vulnerability Overview This vulnerability involves insecure deserialization operations, which can lead to serious security issues such as Remote Code Execution (RCE). ### Scope of Impact - **File …

Read more
Premium intel
CVSS 9.4
Fix for RCE via Unsafe Deserialization in CSV Agent Node Custom Pandas Code
github.com · 2026-08-05

### Vulnerability Overview - **Vulnerability Name**: bug: Block read_pickle and class definitions, restrict custom CSV field to read_csv() only #6257 - **Vulnerability Description**: The CSV Agent Nod…

Read more
mlflow/mlflow at v3.14.0 · mlflow/mlflow · GitHub
github.com · 2026-08-05

### Vulnerability Overview A security vulnerability exists in the `mlflow` project involving the `MLFLOW_ALLOW_PICKLE_DESERIALIZATION` environment variable. This vulnerability allows attackers to exec…

Read more
Release 5.5.3 · tesseract-ocr/tesseract · GitHub
github.com · 2026-08-11

### Vulnerability Overview An integer overflow vulnerability related to LSTM convolution and recrconfig deserialization was discovered in version 5.5.3 of the `tesseract-ocr/tesseract` project. This v…

Read more
[Security]: Update unserialize to use allowed_classes option in Dashb… · pimcore/admin-ui-classic-bundle@80e57a2 · GitHu
github.com · 2026-08-13

### Vulnerability Overview This vulnerability involves updating the `unserialize` function within the `Dashboard` class to use the `allowed_classes` option, thereby mitigating potential deserializatio…

Read more
Release v2.1.18 · basecamp/trix · GitHub
github.com · 2026-08-13

### Vulnerability Overview - **Vulnerability Type**: JSON Drag-and-Drop Deserialization Vulnerability - **Description**: A deserialization vulnerability exists when processing drag-and-drop operations…

Read more
Вышла новая версия 14.0422
vsdesk.ru · 2026-08-20

### Vulnerability Overview In version 14.0422 of vsDesk, multiple security vulnerabilities were fixed, including path traversal, deserialization vulnerabilities, file upload vulnerabilities, and XSS v…

Read more
Premium intel
CVSS 9.8
LMDeploy Pre-Auth RCE via Unsafe Pickle Deserialization in ZMQ (CVE-2026-76850)
www.vulncheck.com · 2026-08-20

### Vulnerability Overview LMDeploy Remote Code Execution Vulnerability: Insecure Pickle Deserialization in the Distributed Service Peer Connector. This vulnerability allows attackers to execute arbit…

Read more
Apache Storm 2.x RCE (CVE-2026-35337) and Stored XSS (CVE-2026-35565) Advisory
storm.apache.org · 2026-04-18

### Vulnerability Overview #### CVE-2026-35337 - Untrusted Data Deserialization Vulnerability - **Description**: When processing topology credentials submitted via the Nimbus Thrift API, Storm deseria…

Read more
CVE-2026-31223 | Notion
www.notion.so · 2026-05-22

# CVE-2026-31223 Vulnerability Summary ## Vulnerability Overview - **Vulnerability ID**: CVE-2026-31223 - **Vulnerability Type**: Unsafe Deserialization (CWE-502) - **Affected Component**: `BaseLabele…

Read more
CVE Record: CVE-2026-24142
www.cve.org · 2026-05-22

# CVE-2026-24142 Vulnerability Summary ## Vulnerability Overview * **Vulnerability ID**: CVE-2026-24142 * **Vulnerability Type**: Deserialization Vulnerability * **Severity**: Medium (CVSS Score: 6.3)…

Read more
Jenkins Security Bulletin: Deserialization, XSS, Auth Bypass (CVE-2026-53435) Patch Guide
www.jenkins.io · 2026-06-13

### Jenkins Security Advisory 2026-06-10 #### Vulnerability Overview 1. **Deserialization Vulnerability** - **CVE**: CVE-2026-53435 - **Severity**: High - **Description**: Jenkins uses serialization a…

Read more
CVE-2026-40993: Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry
spring.io · 2026-06-13

# CVE-2026-40993: Unsanitized Java Native Deserialization SAML 2.0 Asserting Party Credentials Blob Database Entries ## Vulnerability Overview An attacker can store a malicious serialized payload in t…

Read more
Jenkins Security Advisory 2026-06-10
www.jenkins.io · 2026-06-10

### Jenkins Security Advisory 2026-06-10 #### Vulnerability Overview 1. **Deserialization Vulnerability** - **CVE**: CVE-2026-53435 - **Severity**: High - **Description**: Jenkins uses serialization a…

Read more
Apache Camel Security Advisory - CVE-2026-43867 - Apache Camel
camel.apache.org · 2026-07-06

### Vulnerability Overview - **Vulnerability Name**: CVE-2026-43867 - **Severity**: Medium - **Description**: The AWS Secrets Manager key-lifecycle manager reads and deserializes persistent key metada…

Read more
Premium intel
CVSS 9.6
OpenDJ 5.1.2 Security Patch: RCE/SSRF/DoS Fixes (CVE-2026-62373, GHSA)
github.com · 2026-08-14

### Vulnerability Overview This web page screenshot displays the update notes for OpenDJ version 5.1.2, which includes fixes for multiple security vulnerabilities. Below is a summary of the key vulner…

Read more
Premium intel
CVSS 9.8
MaxSite CMS Unauthenticated PHP Object Injection via Cookie (CVE-2026-70554)
www.vulncheck.com · 2026-08-05

# MaxSite CMS Unauthorized PHP Object Injection Vulnerability ## Vulnerability Overview MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to directly invo…

Read more
Keras TFSMLayer Bypasses safe_mode Leading to RCE (CVE-2026-1462)
huntr.com · 2026-04-18

# TFSMLayer Bypass `safe_mode=True` Vulnerability Summary ## Vulnerability Overview **CVE-2026-1462** **Severity**: High (8.8) **Affected Component**: `keras-team/keras` (TFSMLayer class) **Core Issue…

Read more
CVSS 5.3
Blockchain Node DoS Fix: Malicious HistoricTransaction Triggers Panic in History Sync
github.com · 2026-04-23

# Vulnerability Summary ## Overview - **Vulnerability Name**: Fix panic triggered by sync node during historical synchronization. - **Description**: A malicious sync node can cause the sync node to cr…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.