Skip to content
Vulnerability field guide

Insecure Deserialization

When an application rebuilds objects from untrusted serialized data, attacker-crafted gadget chains can run code during deserialization itself. Here is how object injection leads to RCE, and why data-only formats are the fix.

5 articles 20 min total Overview to advanced techniques