Java Deserialization: ObjectInputStream and the Gadget-Chain Problem
Calling ObjectInputStream.readObject() on bytes an attacker controls is enough to reach Runtime.exec during deserialization itself. Here is why a gadget chain runs even though your code never expected that type, and how look-ahead filtering shuts it down.