appsec.fyi

Deserialization — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Deserialization: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 100 of 100 curated resources. Browse all 100 Deserialization resources →

Problem Framing

Deserialization, the process of reconstructing an object from a serialized data format, is a fundamental operation in modern software development. It enables efficient data transfer, state persistence, and communication between components. However, when untrusted data is deserialized without sufficient validation, it creates a significant security risk: Insecure Deserialization. This vulnerability can lead to a range of severe consequences, including arbitrary code execution (RCE), privilege escalation, denial-of-service (DoS) attacks, and data breaches [1][2][3][4][5][6][7]. The OWASP Top 10 consistently highlights Insecure Deserialization as a critical threat, underscoring its pervasive impact across various programming languages and frameworks [1].

The core issue lies in the deserialization process's inherent trust model. When an application deserializes data, it often reconstructs complex object graphs, potentially invoking constructors, setters, and "magic" methods without immediate application-level validation. If an attacker can control the serialized input, they can craft payloads that, during this reconstruction phase, trigger unintended code execution or manipulate application state. This is often achieved by chaining together existing, legitimate code fragments, known as "gadgets," present in the application's dependencies. This technique, known as a gadget chain, allows attackers to leverage the application's own code to achieve malicious objectives, effectively turning a trust boundary into an attack vector [8][9][10][11][5][12][13].

Core Mechanics

At its heart, deserialization takes a byte stream or text representation of an object and reconstructs it in memory. The process varies by language and serialization format, but the fundamental risk arises when the deserializer encounters unexpected or malicious instructions within the serialized data.

In languages like Java, the ObjectInputStream.readObject() method is a common sink. If the input stream contains serialized objects from classes that implement java.io.Serializable, readObject() will reconstruct them. Gadget chains in Java often leverage classes from widely used libraries like Apache Commons Collections or Spring. By controlling the serialized data, an attacker can cause a sequence of method calls (e.g., LazyMap.get() leading to ChainedTransformer.transform()) that ultimately result in executing arbitrary code via Runtime.exec() or similar functions [14][15][16][17]. The ysoserial tool is a prime example of a utility designed to generate such Java deserialization payloads [18][16].

Python's pickle module presents a similar risk. The pickle.loads() function deserializes data, and its documentation explicitly warns against using it with untrusted sources [19][20][21][22]. The __reduce__ magic method is a common target, allowing attackers to return a callable object and its arguments, which pickle.loads() will then execute [19][21][5][6]. YAML parsers like PyYAML also pose risks if used with unsafe loaders, such as yaml.load() without specifying a safe loader, which can lead to arbitrary code execution [19][23][24].

In .NET, various serializers can be exploited. BinaryFormatter is particularly dangerous, as it's known to be insecure by design when handling untrusted data and can lead to arbitrary code execution [25][26][27][28][29]. Other .NET formatters like XmlSerializer, DataContractSerializer, NetDataContractSerializer, and Json.NET (when TypeNameHandling is not None) can also be vulnerable [26][27][30]. Tools like ysoserial.net aid in generating .NET deserialization payloads [31][27].

PHP's unserialize() function is another common vector. It can be exploited via "magic methods" like __wakeup(), __destruct(), and __toString() that are automatically called during deserialization or object destruction. By crafting a malicious serialized string, attackers can instantiate objects that trigger these methods to execute arbitrary PHP code, leading to PHP object injection [32][33][34][35][13][7]. The phar:// stream wrapper in PHP also introduces deserialization vulnerabilities by automatically deserializing the metadata of PHAR archives when accessed [36][33][13].

Ruby's Marshal.load() function is susceptible to deserialization attacks, primarily through gadget chains that leverage standard library classes. Methods like marshal_load, _load, and _load_data are explicit deserialization hooks, but other methods like hash, eql?, and send can also be implicitly triggered during deserialization, forming the basis of exploit chains [37][38][39][40][41][42][43][44].

Serialization Formats and Their Risks

Notable Techniques

The landscape of deserialization vulnerabilities is vast, with numerous techniques and specific instances documented. Attackers commonly exploit these vulnerabilities by leveraging existing code within the application's classpath, a technique known as Property-Oriented Programming (POP) [8][49][24][5].

Gadget Chains

A cornerstone of deserialization exploitation is the gadget chain. This refers to a sequence of method calls on existing objects, triggered during deserialization, that ultimately leads to a dangerous operation like executing arbitrary code. Each object or method in the chain is a "gadget." Gadgets are often found in commonly used libraries due to their widespread presence and often complex internal logic that can be leveraged [50][51][8][9][14][10][11][5][12][16][7].

Specific Vulnerability Classes and Exploitation Methods

Detection and Prevention

Effective detection and prevention of deserialization vulnerabilities require a multi-layered approach, focusing on both code-level controls and runtime monitoring.

Code-Level Practices

Runtime and Monitoring Strategies

Tooling

A variety of tools are available to assist in identifying, generating, and analyzing deserialization exploits.

Payload Generation Tools

Analysis and Detection Tools

Vulnerability Databases and Resources

Recent Developments

The field of deserialization vulnerabilities is continuously evolving, with new research and exploitation techniques emerging regularly. Recent developments highlight several key trends:

Where to Go Deeper

For practitioners seeking to deepen their understanding and practical skills in defending against deserialization attacks, several resources offer invaluable insights:

Sources cited in this guide

  1. Prevent insecure deserialization attacks (Veracode) — docs.veracode.com
  2. Insecure Deserialization: Risks, Examples, and Best Practices — promon.io
  3. Insecure Deserialization Tutorial and Examples — learn.snyk.io
  4. Insecure Deserialization in Web Applications — invicti.com
  5. Insecure Deserialization: The Vulnerability That Gives Attackers RCE — aquilax.ai
  6. Introduction to Deserialization Attacks — owlhacku.com
  7. Insecure deserialization | Web Security Academy — portswigger.net
  8. Depickling, Gadgets, and Chains: The Exploit That Unraveled Equifax — brandur.org
  9. Deserialization Gadget Chain Definition — pentesterlab.com
  10. What Actually Is a Deserialization Gadget Chain? — medium.com
  11. An In-depth Study of Java Deserialization RCE Exploits — dl.acm.org
  12. Now You Serial, Now You Don't — Systematically Hunting for Deserialization Exploits | Google Cloud — cloud.google.com
  13. Exploiting Insecure Deserialization Vulnerabilities | PortSwigger — portswigger.net
  14. Java Deserialization Gadget Chains Explained — klogixsecurity.com
  15. Deserialization Vulnerabilities in Java — baeldung.com
  16. PayloadsAllTheThings - Java Deserialization Payloads — github.com
  17. Insecure Deserialization | OWASP — owasp.org
  18. ysoserial: Java Deserialization Payload Generator — github.com
  19. PayloadsAllTheThings: Insecure Deserialization Python — github.com
  20. Breaking Pickle: RCE Through Python Deserialization — medium.com
  21. Pickle Deserialization in ML Pipelines: The RCE That Won't Go Away — afine.com
  22. Reversing Pickles with r2pickledec — blog.doyensec.com
  23. Docling RCE via PyYAML (CVE-2026-24009) — oligo.security
  24. OWASP Deserialization Cheat Sheet — cheatsheetseries.owasp.org
  25. Master Key Included: Detecting SolarWinds ARM CVE-2026-28326 — bishopfox.com
  26. PayloadsAllTheThings: Insecure Deserialization DotNET — github.com
  27. .NET Deserialization Cheat Sheet — github.com
  28. BinaryFormatter Deserialization Security Guide for .NET — learn.microsoft.com
  29. CVE-2025-34153: Hyland OnBase RCE via Deserialization — sentinelone.com
  30. .NET JSON.NET Deserialization RCE — invicti.com
  31. ysoserial.net: Deserialization Payload Generator for .NET — github.com
  32. picoCTF Super Serial Writeup: PHP Object Injection Explained Clearly — medium.com
  33. PayloadsAllTheThings - PHP Deserialization Payloads — github.com
  34. What is PHP Object Injection? An In-Depth Guide — jetpack.com
  35. PHP Object Injection Research — sonarsource.com
  36. How to Exploit PHAR Deserialization Vulnerability — pentest-tools.com
  37. Ruby Marshal Kick-off Gadgets - elttam — elttam.com
  38. Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam — elttam.com
  39. PayloadsAllTheThings - Ruby Deserialization Payloads — github.com
  40. Ruby Vulnerabilities: Exploiting Open, Send, and Deserialization — bishopfox.com
  41. Marshal Madness: A Brief History of Ruby Deserialization Exploits — blog.trailofbits.com
  42. Unsafe Deserialization in Ruby | SecureFlag — knowledge-base.secureflag.com
  43. Lab: Exploiting Ruby Deserialization Using a Documented Gadget Chain | PortSwigger — portswigger.net
  44. Ruby 2.x Universal RCE Deserialization Gadget Chain | elttam — elttam.com
  45. Deep Dive into Fastjson Deserialization Vulnerabilities — medium.com
  46. Jackson deserialization vulnerability exploit (3 gadgets, GitHub) — github.com
  47. Friday the 13th JSON Attacks (Black Hat) — blackhat.com
  48. SnakeYAML Deserialization Deep Dive (CVE-2022-1471) — greynoise.io
  49. Exploiting PHP Deserialization with POP Chains — medium.com
  50. Precise and Effective Gadget Chain Mining through Deserialization-Guided Call Graph Construction (USENIX Security 2025) — usenix.org
  51. Automated Discovery of Deserialization Gadget Chains (Black Hat) — i.blackhat.com
  52. Java Deserialization Cheat Sheet — github.com
  53. From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX — tantosec.com
  54. Leaking internal headers in Flask Ninja with deserialization — eval.blog
  55. Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) — snyk.io
  56. CVE-2025-24813 PoC: Apache Tomcat Java Deserialization — github.com
  57. WSUS Deserialization Exploit in the Wild (CVE-2025-59287) — research.eye.security
  58. IBM webMethods Integration CVE-2025-36072: Deserialization RCE — zeropath.com
  59. Cisco ISE Insecure Java Deserialization (CVE-2025-20124) — sec.cloudapps.cisco.com
  60. CVE-2023-34040: Spring-Kafka Java Deserialization — spring.io
  61. Apache Struts vulnerability leads to RCE — medium.com
  62. Apache Struts2 Code Execution Exploit (Infopercept) — infopercept.com
  63. Exploiting Apache Struts: Writing Better Detections (Gigamon) — blog.gigamon.com
  64. Insecure Reflection Practices in Java and C# — sprocketsecurity.com
  65. Deep Dive into .NET ViewState Deserialization — swapneildash.medium.com
  66. ViewState Deserialization Zero-Day in Sitecore (CVE-2025-53690) — cloud.google.com
  67. SharePoint Zero-Day CVE-2025-53770 Actively Exploited — blog.checkpoint.com
  68. CVE-2026-25769: Wazuh Critical RCE via Unsafe Deserialization — resecurity.com
  69. SOUR PICKLE: Insecure Deserialization with Python Pickle — medium.com
  70. The Art of Hide and Seek: Pickle-Based Model Supply Chain Poisoning — arxiv.org
  71. PyTorch Users at Risk: 3 Zero-Day PickleScan Vulnerabilities — jfrog.com
  72. Exposing 4 Critical Vulnerabilities in Python Picklescan — sonatype.com
  73. Insecure Deserialization Explained with Examples — thehackerish.com
  74. CVE-2025-42928: SAP jConnect RCE via Deserialization — sentinelone.com
  75. DELMIA Apriso Insecure Deserialization Exploited in the Wild (CVE-2025-5086) — sonicwall.com
  76. Analyzing Prerequisites of Known Deserialization Vulnerabilities on Java Applications — dl.acm.org
  77. Insecure Deserialization Guide - SecPortal — secportal.io
  78. CVE-2025-12305: Shiyi-blog RCE via Deserialization — sentinelone.com
  79. Implant Encryption via the Dump Encoding Library — ipurple.team
  80. Insecure DeserializationWeb ChallengesPart 1 — medium.com
  81. The Anatomy of Deserialization Attacks — cobalt.io
  82. PickleBall: Secure Deserialization of Pickle-based ML Models — arxiv.org
  83. Python-socketio: Pickle deserialization RCE advisory — github.com
  84. Java Deserialization Tricks - Synacktiv — synacktiv.com
  85. Gleipner: A Benchmark for Gadget Chain Detection in Java Deserialization Vulnerabilities — dl.acm.org
  86. Deserialization Gadget Chains in Android: An In-Depth Study — arxiv.org
📚 This guide is synthesized from the full text of resources curated in the Deserialization library, and refreshed as new material is added.