This page is experimental and may change significantly in future releases.
Deserialization of Untrusted Data
Properties
id: d3f:CWE-502
- name
- Deserialization of Untrusted Data
- definition
- The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
- synonyms
- Pickling, Unpickling
- synonyms
- Marshaling, Unmarshaling
- synonyms
- PHP Object Injection
Neighbors
Inferred Relationships
Related Countermeasure Techniques
Related Weaknesses
CWE-502 has no related weaknesses in this release.