Skip to main content

CWE-502: Deserialization of Untrusted Data

BaseDraftExploit Likelihood: Medium🏆 #19 in Top 25 (2024)

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

View on MITRE
237Related CVEs
10.29Severity Score
Back to CWE Lookup

Technical Details

Structure
Simple
Vulnerability Mapping
ALLOWED

Applicable To

Languages
JavaRubyPHPPythonJavaScript
Platforms

🏆 CWE Top 25 Historical Ranking

2023:#15
Score: 5.56
219 CVEs
2024:#19↓4
Score: 10.29
237 CVEs
Trend:Improving (moved up 4 ranks)

Learn More