Insecure Deserialization
Insecure Deserialization: Reconstructing objects from untrusted data, causing attacker-chosen logic to execute. The vulnerability frequently leads straight to remote code executionRemote Code ExecutionVulnerability or attack that allows code to be executed on a remote target..
How it works and where it fits
Serialization converts objects into a transferable representation; deserialization rebuilds them. Powerful formats restore not only data but also type information, and invoke methods while rebuilding — constructors, setters, readObject, __wakeup. An attacker who controls the serialized data therefore also chooses the instantiated types. Through so-called gadget chains, existing application classes are linked so that a system call sits at the end. Java, PHP, Python pickle, and insecurely configured YAML are all affected.
Practical security relevance
Signing or encrypting the serialized blob prevents tampering but does not solve the underlying problem. More robust is a move to purely data-oriented formats without type information, a strict allowlist of permitted classes, and a clear separation between transport format and internal object model. For assessment, the libraries on the class path are decisive — exploitability often depends less on the application than on its dependencies.
Related concepts
- Injection AttackInjection AttackManipulates interpreters or applications via injected commands or data.: Manipulates interpreters or applications via injected commands or data.
- Remote Code ExecutionRemote Code ExecutionVulnerability or attack that allows code to be executed on a remote target.: Vulnerability or attack that allows code to be executed on a remote target.
- Input ValidationInput ValidationVerification of input data regarding format, length, type, value range, and validity.: Verification of input data regarding format, length, type, value range, and validity.
- Java Deserialization VulnerabilityJava Deserialization VulnerabilityVulnerability arising from the processing of manipulated serialized Java objects.: Vulnerability arising from the processing of manipulated serialized Java objects.