Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Security Intel Hub 302— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
TCL 10.0 Insufficient Validation of Serialized Session Data Leading to Memory Safety Issues (CVE-2026-34877)
mbed-tls.readthedocs.io · 2026-04-03

**1. Vulnerability Overview:** * **Title:** Risk of insufficient validation of serialized session or context data leading to potential memory safety issues (CVE-2026-34877) * **Description:** This is …

Read more
Roundcube Redis/RedisCache Session Handler Unsafe Deserialization Arbitrary File Write Fix
github.com · 2026-04-03

### Vulnerability Summary **Vulnerability Overview** A security vulnerability related to unsafe deserialization has been fixed in the Redis/RedisCache session handler of Roundcube email client. The fl…

Read more
Oohu2 Insecure Deserialization RCE Vulnerability and POC
github.com · 2026-04-02

# Oohu2 Remote Code Execution Vulnerability (CVE-2023-XXXX) ## Vulnerability Overview * **Vulnerability Name**: Remote Code Execution via Insecure Deserialization in Oohu2 * **Vulnerability Type**: Re…

Read more
NASA cFS Ground System Deserialization RCE via Pickle
vuldb.com · 2026-04-04

# NASA cFS 7.0.0 Code Execution Vulnerability Summary ### Vulnerability Overview * **Vulnerability Type**: Deserialization Vulnerability / Arbitrary Code Execution * **Affected Component**: NASA cFS G…

Read more
Easy Digital Downloads <=3.3.3 Authenticated PHAR Deserialization (CVE-2022-2439)
www.wordfence.com · 2024-09-25

From this webpage screenshot, the following key vulnerability information can be obtained: 1. **Plugin Name**: Easy Digital Downloads - Simple eCommerce for Selling Digital Files <= 3.3.3 - Authentica…

Read more
Modular Max: Fix RCE risk by removing default Pickle serialization in Zmq Sockets
github.com · 2025-11-19

### Key Information Summary #### Vulnerability Description This commit `ee9c4ab` primarily addresses serialization issues in Zmq Sockets, covering the following aspects: 1. **Removal of Default Pickle…

Read more
GPT-SoVITS Multiple Deserialization RCE Vulnerabilities (CVE-2025-49837 to 49841)
securitylab.github.com · 2025-07-17

### Critical Vulnerability Information #### Vulnerability IDs - GHSL-2025-049 - GHSL-2025-053 #### Vulnerability Type - Remote Code Execution (RCE) #### Affected Component - GPT-SoVITS #### Related CV…

Read more
Roundcube Fix Unsafe Deserialization Arbitrary File Write and INP Injection
github.com · 2026-04-03

### Vulnerability Overview This update addresses two critical security vulnerabilities: 1. **INP Injection and CRLF Bypass**: A vulnerability exists in the mail search functionality, allowing INP inje…

Read more
Fix: Remote Code Execution via Jinacore Deserialization in OkAuth
github.com · 2026-04-02

### Vulnerability Summary **Vulnerability Overview** * **Vulnerability Type**: Remote Code Execution (RCE) * **Root Cause**: Deserialization vulnerability in the `Jinacore` component within `OkAuth`. …

Read more
Roundcube: Fix Arbitrary File Write via Unsafe Deserialization in redis/newcache Session Handler
github.com · 2026-04-03

### Vulnerability Overview This screenshot presents a security fix commit (Commit 44e4d99) in the Roundcube email client. It addresses an **arbitrary file write vulnerability** caused by **unsafe dese…

Read more
systemd CVE-2018-15686: Serialization/Deserialization Vulnerability Fix Analysis
github.com · 2025-11-11

## Vulnerability Key Information - **CVE ID**: CVE-2018-15686 - **Vulnerability Description**: - This Pull Request (PR) introduced an alert indicating a comparison result is always the same, affecting…

Read more
CVE-502: RCE via Unsafe Pickle Deserialization in Async Inference Pipeline
github.com · 2026-04-24

# Vulnerability Summary ## Overview - **Vulnerability ID**: CVE-502 (Deserialization of Untrusted Data) - **Description**: In the asynchronous inference pipeline, there exist unsafe calls to `pickle.l…

Read more
RCE in langgraph-checkpoint JsonPlusSerializer via Unsafe Deserialization
github.com · 2025-11-09

## Vulnerability Overview ### Vulnerability Name RCE in "json" mode of JsonPlusSerializer ### Affected Versions langgraph-checkpoint 3.0 ### Vulnerability Description Prior to version 3.0, JsonPlusSer…

Read more
RCE via Unsafe Deserialization in jsonpickle.loads
huntr.com · 2025-07-12

## Critical Vulnerability Information ### Vulnerability Description - **Type**: Unsafe Deserialization (`jsonpickle.loads`) - **Impact**: Remote Code Execution (RCE) - **Cause**: The `jsonpickle.loads…

Read more
CVE-2022-2265 Replicant Insecure Deserialization RCE
morielharush.github.io · 2026-04-02

# Replicant: When Deserialization Starts Writing Your Scripts ## Vulnerability Overview **Replicant** is an npm package for advanced JavaScript serialization and deserialization. This vulnerability (C…

Read more
Red Hat JBoss EAP 6.4.20 Security Update (RHSA-2018:1450)
access.redhat.com · 2025-11-11

### Vulnerability Key Information - **Announcement ID**: RHSA-2018:1450 - **Release Date**: 2018-05-14 - **Update Date**: 2018-05-14 - **Type/Severity**: Important - **Subject**: Red Hat JBoss Enterpr…

Read more
openITCOCKPIT v5.3.1 Unsafe PHP Deserialization Vulnerability Analysis
github.com · 2026-02-21

# Critical Vulnerability Summary ## Affected Products and Versions - **Product**: openITCOCKPIT Community Edition - **Version**: v5.3.1 ## Vulnerability Category - Insecure Deserialization - PHP Objec…

Read more
NutzBoot LiteRPC Unauthenticated Java Deserialization RCE
github.com · 2025-12-04

### Key Information Extraction #### Affected Products - NutzBoot (LiteRPC + Loach modules) #### Version Information - **Affected Versions**: 2.6.0-SNAPSHOT (current dev branch, check specific commits …

Read more
Roundcube Webmail: Fix Arbitrary File Write via Unsafe Deserialization in Redis/Memcache Session Handler
github.com · 2026-04-03

### Vulnerability Overview Roundcube Webmail has fixed a critical security vulnerability. The issue resides in the `redis/memcache session handler`, where **unsafe deserialization** allows remote atta…

Read more
Zumba JsonSerializer Unsafe Deserialization Fix
github.com · 2026-02-21

# Critical Vulnerability Information ## Vulnerability Description In the `Zumba\JsonSerializer` library, there is an **insecure deserialization vulnerability** that could lead to Remote Code Execution…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.