#deserialization

kriware :verified:kriware@infosec.exchange
2025-11-02

CVE-2025-59287 WSUS Unauthenticated RCE

Vulnerability in update service enables unauthenticated attacker to send crafted encrypted cookie leading to unsafe deserialization and SYSTEM-level code execution

hawktrace.com/blog/CVE-2025-59

#Deserialization #PatchMgmt

I built a tiny/simple ECS library for a hobby game. I like defining "prefabs" in code, but I'm wracking my brain trying to understand how I can have code-defined prefabs, but also make a lightweight editor where I can place entities and edit attributes about that "instance" in the level, save it, and have that deserialized data be applied on top of the prefab during deserialization/gameplay.

Any hobbiests out there, I could use your insights.

#ecs #deserialization #leveleditors #helpwanted

Offensive Sequenceoffseq@infosec.exchange
2025-09-01

🚨 CVE-2025-6507 (CRITICAL, CVSS 9.8): h2oai/h2o-3 vulnerable to remote code execution & file read via deserialization flaw in JDBC handling. Upgrade to 3.46.0.8+ ASAP! radar.offseq.com/threat/cve-20 #OffSeq #CVE20256507 #AIsecurity #Deserialization

Critical threat: CVE-2025-6507: CWE-502 Deserialization of Untrusted Data in h2oai h2oai/h2o-3
Offensive Sequenceoffseq@infosec.exchange
2025-07-08

🔴 CRITICAL: CVE-2025-42980 in SAP NetWeaver EP-RUNTIME 7.50 exposes deserialization of untrusted data. Privileged users can trigger full system compromise. Apply patches & review privileges. radar.offseq.com/threat/cve-20 #OffSeq #SAP #CVE202542980 #Deserialization #Vuln

Critical threat: CVE-2025-42980: CWE-502: Deserialization of Untrusted Data in SAP_SE SAP NetWeaver Enterprise Portal
2025-07-07

💣 CLIXML #deserialization in #PowerShell isn't harmless… At #PSConfEU 2025, Alexander Andersson showed how it enables: ✔ Lateral movement ✔ Privilege escalation ✔ Guest-to-host VM breakouts 🎟️ Early bird 2026 tickets → psconf.eu #Security #CLIXML

- YouTube

TechKeysXTechKeysX
2025-06-04

Using JsonPropertyName to map Json to Class C# Tip #42 - How to use the [JsonPropertyName] attribute in C# to map mismatched JSON fields (like "id") to class properties (like UniquePostId) during deserialization.

2025-05-30
[oss-security] CVE-2025-48734: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default

https://www.openwall.com/lists/oss-security/2025/05/28/6

I wonder if the now restricted behavior is useful for #deserialization gadgets (I couldn't find references to declaredClass abuse, but haven't finished my coffee yet either...)?
Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2025-05-21

Seems a first step is almost done, adding #JSON support to my #poser lib. This could be the foundation for #JWT support in #swad. 😎

Need to do more thorough testing I guess, but at least the two example documents from #rfc8259 work fine ... the test tool does a full #deserialization / #serialization roundtrip (with specific internal representations of the data types supported by JSON).

edit: Look at the "Longitude" value of the second object in the second example 😏 I only noticed myself right now, but of course that's the desired behavior.

Testing JSON serialization in poser with the examples provided by RFC 8259
2024-12-20

My first article for @mogwailabs_gmbh just released. Thanks to @h0ng10 for making it happen. 🥳

mogwailabs.de/en/blog/2024/12/

#jndi #java #deserialization

2024-11-25

Note: before all of the script kiddies get their hopes up and think they can pwnxorize every Rails app, deserialization vulnerabilities in Ruby are actually quite rare these days due to Marshal.load almost never being used in the wild and YAML.load has been aliased to YAML.safe_load for some time now.
#rubysec #deserialization

BaselOneBaselOne
2024-10-09

🚀 Nächste Woche ist 🎉

Am 16. und 17. Oktober 2024 erwarten Euch viele spannende Workshops und Vorträge von bekannten Speaker:innen und Newcomer:innen. Dabei bringen Sie Euch auf den neuesten Stand in Sachen , , , , , , , und vieles mehr.

👉🏻 Hier geht's zum Programm: lnkd.in/egfakuP5

🐸 lnkd.in/ggjmzerN

BaselOneBaselOne
2024-09-25

⏳Wer hat an der Uhr gedreht... Nur noch 3 Wochen bis zur ... 😊

🔊 Am 16. und 17. Oktober 2024 erwarten Euch Gerrit Grunwald, Grace Jansen, Falk Sippach, Nadine Broghammer, Simon Martinelli und Patrick Baumgartner. Dabei bringen Sie Euch auf den neuesten Stand in Sachen , , , , hashtag#Java, , , und vieles mehr.

🐸 unter lnkd.in/ggjmzerN.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst