Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 553— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Premium intel
CVSS 3.7
Roundcube Webmail: Fix Arbitrary File Write via Unsafe Deserialization in Redis/Memcache Session Handler
github.com · 2026-04-03

### Vulnerability Overview Roundcube Webmail has fixed a critical security vulnerability. The issue resides in the `redis/memcache session handler`, where **unsafe deserialization** allows remote atta…

Read more
CVSS 7.3
FedML-AI <=0.8.9 gRPC Insecure Deserialization RCE
vuldb.com · 2026-04-05

## Vulnerability Key Information ### Vulnerability Overview | Item | Content | |:---|:---| | **Vulnerability ID** | Submit #782201 / VulnDB 355289 | | **Vulnerability Title** | FedML-AI FedML **Note**…

Read more
HPX v1.11.0 Unsafe Deserialization Type Confusion Leading to RCE
gist.github.com · 2026-04-29

# Vulnerability Summary: HPX v1.11.0 Deserialization Type Confusion ## Vulnerability Overview An unsafe deserialization vulnerability was discovered in HPX v1.11.0 and earlier versions. Due to insuffi…

Read more
Premium intel
CVSS 6.4
aiohttp CookieJar.load() Pickle Deserialization RCE Vulnerability Analysis
github.com · 2026-06-03

### Vulnerability Overview This vulnerability relates to the lack of restrictions on pickle deserialization in the `CookieJar.load()` method. Specifically, when loading cookie data in pickle format, t…

Read more
Premium intel
CVSS 7.5
Spinnaker KustomizationFileReader YAML Unsafe Deserialization RCE Analysis
github.com · 2026-07-11

### Vulnerability Overview This vulnerability involves the unsafe deserialization method used when parsing YAML files, allowing attackers to execute arbitrary code by crafting malicious YAML files. Sp…

Read more
Symfony Monolog ServerLog Unserialize RCE Fix via allowed_classes Restriction
github.com · 2026-07-15

### Vulnerability Overview The attached webpage screenshot shows a commit addressing a vulnerability fix in the Symfony framework. The vulnerability involves deserialization issues when handling log m…

Read more
CVE-2026-31234 | Notion
www.notion.so · 2026-05-22

# CVE-2026-31234 ## Vulnerability Overview CVE-2026-31234 is an unauthenticated pickle deserialization vulnerability located in the KVStore component of Horovod. Attackers can achieve Remote Code Exec…

Read more
FREEI-2684 Reduce risk of RCE during restore operation · FreePBX/backup@64781af · GitHub
github.com · 2026-05-22

# FreePBX Backup Module Remote Code Execution Vulnerability (FREEI-2084) ## Vulnerability Overview The backup module in FreePBX is vulnerable to Remote Code Execution (RCE) during restore operations. …

Read more
Merge commit from fork · simplesamlphp/simplesamlphp-module-casserver@b84f3e4 · GitHub
github.com · 2026-06-13

### Vulnerability Overview This vulnerability concerns a security issue in the file system storage mechanism within the CAS (Central Authentication Service) module. The specific remediation steps incl…

Read more
DynamicUnionResolver generated deserializers miss depth enforcement · Advisory · MessagePack-CSharp/MessagePack-CSharp ·
github.com · 2026-06-27

# Vulnerability Overview - **Vulnerability Name**: DynamicUnionResolver generated deserializers miss depth enforcement - **Vulnerability ID**: GHSA-wfr3-xj75-pf9h - **Severity**: Moderate - **CVSS v4 …

Read more
Pyro 3.x Unsafe Pickle Deserialization Leads to Unauthenticated RCE
github.com · 2026-04-18

# Vulnerability Overview Pyro 3.x contains an insecure pickle deserialization vulnerability. An attacker can send a specially crafted serialized payload to a Pyro 3.x server and exploit Python’s `pick…

Read more
H2O Unauthenticated RCE via Unrestricted JDBC URL Injection Leading to Deserialization and Command Execution
spear-shield.notion.site · 2024-09-07

From this webpage screenshot, the following key information about the vulnerability can be obtained: 1. **Vulnerability Type**: Unauthenticated Remote Code Execution (RCE). 2. **Vulnerability Descript…

Read more
CVSS 9.9
Kibana YAML Deserialization RCE Vulnerabilities (CVE-2024-37288/37285) and Mitigation
discuss.elastic.co · 2024-09-10

From this webpage screenshot, the following key vulnerability information can be obtained: 1. **Vulnerability Description**: - **Title**: Kibana arbitrary code execution via YAML deserialization in Am…

Read more
Premium intel
CVSS 9.0
SolarWinds ARM Hardcoded Creds Auth Bypass & Deserialization RCE (CVE-2024-28990/28991)
documentation.solarwinds.com · 2024-09-13

From this webpage screenshot, the following key information about the vulnerabilities can be obtained: 1. **Vulnerability IDs and Descriptions**: - **CVE-2024-28990**: SolarWinds Access Rights Manager…

Read more
Apache Seata Hessian Deserialization RCE Vulnerability (CVE-2024-22399) Advisory
lists.apache.org · 2024-09-17

### Key Information - **CVE Number**: CVE-2024-22399 - **Vulnerability Name**: Apache Seata: Remote Code Execution vulnerability via Hessian Deserialization in Apache Seata Server - **Release Date**: …

Read more
CVSS 5.1
Apache Lucene Replicator Deserialization Vulnerability Advisory (CVE-2024-45772)
lists.apache.org · 2024-10-01

### Key Information - **Vulnerability ID**: CVE-2024-45772 - **Vulnerability Name**: Apache Lucene Replicator: Security Vulnerability in Lucene Replicator - Deserialization Issue - **Release Platform*…

Read more
CVE-2024-47561: Apache Avro Java SDK Arbitrary Code Execution via Schema Parsing
lists.apache.org · 2024-10-07

### CVE-2024-47561: Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK) #### Key Information from the Webpage Screenshot: 1. **Severity**: Critical 2. **Affected Versions*…

Read more
Apache Batik/FOP/XML Graphics Commons SSRF/XXE/Deserialization Vulnerabilities Summary (CVE-2022-44729 etc.)
xmlgraphics.apache.org · 2024-10-10

From this webpage screenshot, the following key information about vulnerabilities can be obtained: 1. **Apache Batik Project - Apache Batik Security**: - Batik 1.17: SSRF vulnerability CVE-2022-44729 …

Read more
pac4j-core Java Deserialization RCE (CVE-2023-25581)
securitylab.github.com · 2024-10-12

From this webpage screenshot, the following key information about the vulnerability can be obtained: 1. **Vulnerability ID and Name**: - Vulnerability ID: GHSL-2022-085 - Vulnerability Name: Java dese…

Read more
Chainer CVE-2024-48206 Deserialization Vulnerability Analysis
gist.github.com · 2024-11-03

From this webpage screenshot, the following key information about the vulnerability can be obtained: 1. **Vulnerability ID**: CVE-2024-48206 2. **Description**: Chainer v7.8.1.post1 contains a vulnera…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.