Critical severity Vulnerability

Insecure Deserialization

Trusting serialized objects from the client allows remote code execution through gadget chains.

Overview

When an application unserializes data it did not create, an attacker can inject an object whose magic methods trigger file writes, database calls or command execution.\nPHP, Java, Python and .NET all have known gadget chains, so the fix is never to deserialize untrusted input.\nSigned tokens or explicit data-mapping formats such as JSON are the safe alternatives.

Indicators of Compromise

Signals that suggest this is present on a system.

  • base64 blobs containing O: or similar type markers
  • Session payloads that are not plain JSON
  • Unexpected objects appearing after cookie edits

Controls that stop it

  • Validate and Constrain All Input

    Treat every request as hostile. Reject anything that does not match an allow list, enforce type, length, range and format, and canonicalise before you validate so encoded bypasses cannot slip through. For file uploads, re-encode the image, randomise the name, strip metadata and store outside the web root on a domain that cannot execute code.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used