CWE-502

Deserialization of Untrusted Data

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Diagram

Diagram illustrating CWE-502: Deserialization of Untrusted Data

Source: MITRE CWE™ — CWE-502

CWE-502: Deserialization of Untrusted Data — CVE Insight