Problem Framing
Deserialization, the process of reconstructing an object from a serialized data format, is a fundamental operation in modern software development. It enables efficient data transfer, state persistence, and communication between components. However, when untrusted data is deserialized without sufficient validation, it creates a significant security risk: Insecure Deserialization. This vulnerability can lead to a range of severe consequences, including arbitrary code execution (RCE), privilege escalation, denial-of-service (DoS) attacks, and data breaches [1][2][3][4][5][6][7]. The OWASP Top 10 consistently highlights Insecure Deserialization as a critical threat, underscoring its pervasive impact across various programming languages and frameworks [1].
The core issue lies in the deserialization process's inherent trust model. When an application deserializes data, it often reconstructs complex object graphs, potentially invoking constructors, setters, and "magic" methods without immediate application-level validation. If an attacker can control the serialized input, they can craft payloads that, during this reconstruction phase, trigger unintended code execution or manipulate application state. This is often achieved by chaining together existing, legitimate code fragments, known as "gadgets," present in the application's dependencies. This technique, known as a gadget chain, allows attackers to leverage the application's own code to achieve malicious objectives, effectively turning a trust boundary into an attack vector [8][9][10][11][5][12][13].
Core Mechanics
At its heart, deserialization takes a byte stream or text representation of an object and reconstructs it in memory. The process varies by language and serialization format, but the fundamental risk arises when the deserializer encounters unexpected or malicious instructions within the serialized data.
In languages like Java, the ObjectInputStream.readObject() method is a common sink. If the input stream contains serialized objects from classes that implement java.io.Serializable, readObject() will reconstruct them. Gadget chains in Java often leverage classes from widely used libraries like Apache Commons Collections or Spring. By controlling the serialized data, an attacker can cause a sequence of method calls (e.g., LazyMap.get() leading to ChainedTransformer.transform()) that ultimately result in executing arbitrary code via Runtime.exec() or similar functions [14][15][16][17]. The ysoserial tool is a prime example of a utility designed to generate such Java deserialization payloads [18][16].
Python's pickle module presents a similar risk. The pickle.loads() function deserializes data, and its documentation explicitly warns against using it with untrusted sources [19][20][21][22]. The __reduce__ magic method is a common target, allowing attackers to return a callable object and its arguments, which pickle.loads() will then execute [19][21][5][6]. YAML parsers like PyYAML also pose risks if used with unsafe loaders, such as yaml.load() without specifying a safe loader, which can lead to arbitrary code execution [19][23][24].
In .NET, various serializers can be exploited. BinaryFormatter is particularly dangerous, as it's known to be insecure by design when handling untrusted data and can lead to arbitrary code execution [25][26][27][28][29]. Other .NET formatters like XmlSerializer, DataContractSerializer, NetDataContractSerializer, and Json.NET (when TypeNameHandling is not None) can also be vulnerable [26][27][30]. Tools like ysoserial.net aid in generating .NET deserialization payloads [31][27].
PHP's unserialize() function is another common vector. It can be exploited via "magic methods" like __wakeup(), __destruct(), and __toString() that are automatically called during deserialization or object destruction. By crafting a malicious serialized string, attackers can instantiate objects that trigger these methods to execute arbitrary PHP code, leading to PHP object injection [32][33][34][35][13][7]. The phar:// stream wrapper in PHP also introduces deserialization vulnerabilities by automatically deserializing the metadata of PHAR archives when accessed [36][33][13].
Ruby's Marshal.load() function is susceptible to deserialization attacks, primarily through gadget chains that leverage standard library classes. Methods like marshal_load, _load, and _load_data are explicit deserialization hooks, but other methods like hash, eql?, and send can also be implicitly triggered during deserialization, forming the basis of exploit chains [37][38][39][40][41][42][43][44].
Serialization Formats and Their Risks
- Java Serialization: Native binary serialization, often leading to RCE via gadget chains. Requires classes to implement
Serializable.ObjectInputStream.readObject()is a primary sink [14][15][16][17][7]. - Python Pickle: Supports complex object serialization, including code execution via
__reduce__. Explicitly warned against for untrusted data [19][20][21][6][22][5]. - .NET BinaryFormatter: Inherently insecure for untrusted data, allowing arbitrary code execution. Other .NET serializers can also be vulnerable under certain configurations [25][26][27][28][29].
- PHP Serialization: Exploitable via magic methods (
__wakeup,__destruct) andphar://wrapper metadata deserialization [32][33][34][35][13][7]. - Ruby Marshal: Susceptible to gadget chains leveraging standard library classes, often triggered implicitly during deserialization [37][38][39][40][41][42][43][44].
- JSON/XML/YAML: While generally safer as they primarily handle data structures, they can be vulnerable if specific implementations or libraries (e.g., PyYAML's unsafe loaders, Jackson's polymorphic type handling) deserialize objects rather than just data [45][46][47][19][48][23][24][4].
Notable Techniques
The landscape of deserialization vulnerabilities is vast, with numerous techniques and specific instances documented. Attackers commonly exploit these vulnerabilities by leveraging existing code within the application's classpath, a technique known as Property-Oriented Programming (POP) [8][49][24][5].
Gadget Chains
A cornerstone of deserialization exploitation is the gadget chain. This refers to a sequence of method calls on existing objects, triggered during deserialization, that ultimately leads to a dangerous operation like executing arbitrary code. Each object or method in the chain is a "gadget." Gadgets are often found in commonly used libraries due to their widespread presence and often complex internal logic that can be leveraged [50][51][8][9][14][10][11][5][12][16][7].
- Java Gadget Chains: Tools like
ysoserialcatalog numerous Java gadget chains, often based on libraries like Apache Commons Collections, Spring, and Hibernate. For instance, theCommonsCollections1chain utilizesLazyMapandChainedTransformerto achieve RCE [14][18][52][16]. - .NET Gadget Chains:
ysoserial.netprovides similar functionality for .NET, with gadgets leveraging classes likeObjectDataProvider,ActivitySurrogateSelector, andSystem.Configuration.Install.AssemblyInstaller[26][31][27]. - PHP POP Chains: In PHP, Property-Oriented Programming (POP) chains leverage magic methods within classes to control application flow, achieving RCE or other malicious actions [49][35][13].
- Ruby Gadget Chains: Ruby deserialization exploits often involve chaining methods from the standard library, such as those found in
Gem::StubSpecificationorNet::WriteAdapter, to invoke system commands [37][38][39][41][43][44].
Specific Vulnerability Classes and Exploitation Methods
- SolarWinds Access Rights Manager (CVE-2026-26283): This vulnerability exploited .NET
BinaryFormatterdeserialization via a gRPC listener. A hardcoded shared secret allowed unauthenticated RCE by bypassing TLS client certificate authentication [25]. - Telerik UI for ASP.NET AJAX (Unauthenticated RCE): An AES-CBC padding oracle vulnerability, chained with other flaws, allowed RCE. It required a specific
RadAsyncUploadcontrol and a non-defaultTelerik.AsyncUpload.ConfigurationEncryptionKey[53]. - Ruby Marshal Deserialization: Various vulnerabilities exist, including those exploiting
marshal_load,_load,_load_data, and implicit gadget calls likehashonGem::StubSpecification. These often lead to RCE by chaining methods to invokeKernel.systemoreval[37][38][39][41][43][44]. - Flask Ninja & Pickle/Pydantic: Flask Ninja's
HttpBearerclass could be exploited via deserialization if an attacker could control theheaderandopenapi_schemeattributes, leading to sensitive header leakage. This also applied if configuration was loaded insecurely via Pydantic models [54]. - React Server Components (RSC) / Next.js (CVE-2025-55182): Insecure deserialization of the "Flight" protocol payloads in RSC led to unauthenticated RCE. Exploitation required a crafted HTTP request targeting RSC endpoints [55].
- Apache Tomcat Java Deserialization (CVE-2025-24813): Exploitable via Java deserialization, often utilizing
ysoserialto generate payloads targeting known gadget chains [56]. - WSUS Deserialization (CVE-2025-59287): Exploited unsafe deserialization in WSUS, evidenced by
ThreadAbortExceptionand the presence ofysoserial.netgadget chains within log files [57]. - IBM webMethods Integration Server (CVE-2025-36072): An authenticated deserialization RCE vulnerability allowing attackers to leverage gadget chains present in the classpath by submitting crafted serialized Java object graphs via internal APIs like
IDataBin[58]. - Cisco ISE Insecure Java Deserialization (CVE-2025-20124): Exploited Java deserialization vulnerabilities, requiring gadget chains to achieve RCE [59].
- Spring-Kafka (CVE-2023-34040): A deserialization attack vector existed in exception record headers, but only under specific, unusual configurations requiring an
ErrorHandlingDeserializerand malicious serialized objects within headers [60]. - Jackson Deserialization Vulnerabilities: Exploitation via Polymorphic Type Handling (PTH) when enabled insecurely. Gadgets like
TemplatesImplcan be triggered [46]. - Apache Struts: Vulnerabilities, notably those involving XStream, allowed RCE via insecure XML deserialization of POST requests with
application/xmlcontent type. Gadget chains are leveraged [61][62][63][8][52]. - .NET ViewState Deserialization: ASP.NET ViewState can be exploited if the
machineKeyis compromised. Attackers can craft malicious serialized objects (often usingysoserial.net) that are deserialized byLosFormatterorObjectStateFormatter, leading to RCE [64][65][66][67][27]. - PHP PHAR Deserialization: Abuses the
phar://stream wrapper, causing metadata to be deserialized, enabling POP attacks via magic methods like__destruct()[36][33][13]. - .NET
BinaryFormatter: Widely recognized as insecure. Exploited in various products, including SolarWinds ARM, Hyland OnBase, and Microsoft Exchange, often requiring specific gadget chains [25][28][29][27]. - Wazuh Cluster Communication (CVE-2026-33728): Unsafe JSON deserialization via a custom
object_hookallowed RCE on the master node by importing arbitrary modules and executing functions, breaking the data/code boundary [68]. - Sitecore ViewState Deserialization (CVE-2025-53690): Exploits insecure deserialization of ASP.NET ViewState when the
machineKeyis exposed, allowing RCE with high privileges [66]. - SnakeYAML Deserialization (CVE-2022-1471): Versions before 2.0 allow RCE by parsing untrusted YAML with unsafe defaults, enabling arbitrary class instantiation [48].
- PyYAML Deserialization: Used in various applications, unsafe loading (
yaml.unsafe_load,yaml.load(Loader=yaml.UnsafeLoader)) can lead to RCE. This is often a "shadow vulnerability" inherited through dependencies [19][23][24]. - Python Pickle: Ubiquitous in ML frameworks. Vulnerable when
pickle.load()orpickle.loads()is used on untrusted data, especially in model loading pipelines. Tools likepicklescanattempt to mitigate this but can be bypassed [69][19][70][71][72][20][21][3][5][73][6][22]. - Hyland OnBase (CVE-2025-34153): Unauthenticated RCE via
.NET RemotingusingBinaryFormatteron the Timer Service, grantingSYSTEMprivileges [29]. - SAP jConnect Deserialization (CVE-2025-42928): Authenticated RCE for high-privilege users by exploiting deserialization flaws in
jConnect, leveraging Java gadget chains [74]. - DELMIA Apriso Insecure Deserialization (CVE-2025-5086): Unsafe deserialization using
NetDataContractSerializerin WCF services, allowing RCE without authentication [75]. - Java Deserialization in general: Beyond specific libraries,
ObjectInputStream.resolveClass()andObjectInputStream.readObject()are fundamental sinks. JEP 290 provides serialization filtering capabilities to mitigate risks [24][52][76][17][7]. - PHP Object Injection: Exploits
unserialize()with user-controlled input, often targeting magic methods andphar://wrapper [32][33][34][35][13][7].
Detection and Prevention
Effective detection and prevention of deserialization vulnerabilities require a multi-layered approach, focusing on both code-level controls and runtime monitoring.
Code-Level Practices
- Avoid Deserializing Untrusted Data: The most robust defense is to never deserialize data from untrusted or unauthenticated sources. If serialized data must be handled, it should originate from trusted internal systems or undergo rigorous validation [1][2][24][4][77][5][17][6][7].
- Use Safer Serialization Formats: Whenever possible, opt for data-only formats like JSON, XML, or YAML (with safe loaders) that do not reconstruct arbitrary objects. These formats are generally less prone to RCE through gadget chains [1][8][24][5][17][7].
- Input Validation and Sanitization: If deserialization is unavoidable, implement strict validation and sanitization of the input data before deserialization. This includes checking data types, lengths, and formats [2][24][4][68].
- Serialization Filters/Allowlisting: For languages like Java, utilize serialization filtering mechanisms (e.g., JEP 290's
ObjectInputFilter) to define an explicit allowlist of classes that are permitted to be deserialized [24][29][17]. Similarly, in .NET withJson.NET, settingTypeNameHandlingtoNoneor implementing a strictSerializationBinderis crucial [30]. - Integrity Checks: Employ digital signatures, HMACs, or cryptographic hashes to verify the integrity of serialized data before deserialization. This prevents tampering with the payload [1][2][4][77][5].
- Minimize Dependencies: Reduce the attack surface by minimizing external library dependencies. Each dependency can potentially introduce new gadget chains [8][5][7].
- Secure Configuration: Avoid hardcoded secrets or default configurations that can be exploited, as seen in the SolarWinds ARM vulnerability [25].
- Principle of Least Privilege: Run deserialization code in low-privilege environments to limit the impact of a successful exploitation [1][78][29].
- Disable Dangerous Serializers: Avoid known insecure serializers like .NET's
BinaryFormatterand PHP'sunserialize()on untrusted input [27][28][24][77].
Runtime and Monitoring Strategies
- Intrusion Detection Systems (IDS) and Web Application Firewalls (WAF): WAFs can block known malicious payloads or suspicious patterns in serialized data. IDS can detect anomalous network traffic or process behavior associated with deserialization attacks [55][57][23][78][29].
- Endpoint Detection and Response (EDR): EDR solutions can monitor for suspicious process creation, file system activity, or network connections that might indicate deserialization exploitation [79][57][78][29].
- Logging and Auditing: Comprehensive logging of deserialization events, exceptions, and access attempts can provide critical forensic data and aid in detecting suspicious activity [1][78].
- Behavioral Analysis: Monitoring for unusual memory, CPU, file system, or network usage during deserialization operations can flag potential DoS or RCE attacks [1][17].
- Dependency Scanning: Regularly scan project dependencies for known vulnerable serialization libraries and promptly apply patches [55][71][72].
- Static and Dynamic Analysis Tools (SAST/DAST): SAST tools can identify potential deserialization sinks in source code, while DAST tools can detect exploitable vulnerabilities in running applications [1][23][80].
- Specific Pattern Matching: Look for characteristic byte sequences (e.g.,
AC ED 00 05for Java,rO0for Base64-encoded Java) or patterns indicative of serialized data in network traffic or logs [81][24][52][16][13]. - Sysmon Configurations: Custom Sysmon rules can monitor for specific DLL loads (e.g.,
WerEnc.dll) or file creation events related to deserialization tools [79].
Tooling
A variety of tools are available to assist in identifying, generating, and analyzing deserialization exploits.
Payload Generation Tools
ysoserial: A well-known Java tool for generating deserialization payloads for various gadget chains and Java versions. It supports numerous libraries and commands [18][52][16][13].ysoserial.net: The .NET equivalent ofysoserial, used for generating payloads targeting .NET deserialization vulnerabilities across different formatters [26][31][27].phpggc: A tool for generating PHP object injection payloads for various frameworks like Laravel, Symfony, and Monolog [33].jexboss: A Java deserialization verification and exploitation tool [52][16].marshalsec: A Java tool for discovering and exploiting deserialization vulnerabilities, including RMI and JNDI exploitation [52][16].
Analysis and Detection Tools
- Burp Suite: Burp Scanner can automatically flag HTTP messages containing serialized objects. Extensions integrate with
ysoserialfor exploit generation and detection [12][16][13]. - Radare2 with
r2pickledec: A plugin for reversing and decompiling Python pickle files [22]. picklescan: A tool designed to scan Python pickle files for malicious content, though it has known bypasses [71][72].gadgetprobe: A tool for exploiting deserialization by brute-forcing the remote classpath to find gadgets [16].SerialKiller: A Java library for protecting against deserialization attacks by filtering deserialized classes [24][52][16].Java Deserialization Scanner: A Burp Suite plugin for detecting and exploiting Java deserialization vulnerabilities [52][16].heyserial.py/checkyoself.py: Tools developed by Mandiant for generating hunting rules for deserialization exploits [12].
Vulnerability Databases and Resources
- OWASP Top 10: Consistently lists Insecure Deserialization as a critical risk [1][24][5][7].
- PayloadsAllTheThings: A comprehensive GitHub repository containing various deserialization payloads and cheat sheets for different languages [26][19][39][33][27][52][16].
- CVE Databases (NVD, MITRE): Essential for tracking specific deserialization vulnerabilities and their details [25][53][55][57][58][59][60][66][67][75][68][78][29][74].
Recent Developments
The field of deserialization vulnerabilities is continuously evolving, with new research and exploitation techniques emerging regularly. Recent developments highlight several key trends:
- Increased Sophistication in Gadget Discovery: Automated tools and advanced static/dynamic analysis are becoming more effective at finding novel gadget chains across complex codebases and dependencies [50][51][70][82][76]. This includes techniques like "Exception-Oriented Programming" (EOP) to bypass scanners [70].
- Supply Chain Attacks: Deserialization vulnerabilities are increasingly being weaponized in supply chain attacks, particularly in the AI/ML ecosystem. Malicious pickle files containing RCE payloads are distributed through model-sharing platforms like Hugging Face, bypassing existing security scanners [70][71][72][21][3].
- "Shadow Vulnerabilities": Flaws introduced through transitive dependencies, where a library uses an insecure deserialization function without the main application directly importing it, are becoming more prevalent and harder to detect with traditional static analysis [23].
- Exploitation in Cloud-Native Environments: Vulnerabilities in distributed systems, message queues (e.g., Python-socketio), and microservices highlight the need for secure inter-service communication and data handling, even when using ostensibly safer formats like JSON if not configured correctly [83][68].
- Framework-Specific Vulnerabilities: Frameworks like React Server Components (RSC) and .NET Remoting have had critical deserialization flaws that enabled RCE, underscoring the need for secure handling of protocol-specific data [25][55][29].
- Bypassing Security Controls: Attackers are developing techniques to bypass WAFs, EDRs, and model scanners by obfuscating payloads, renaming classes, or exploiting specific logic flaws in detection mechanisms [84][71][72].
- Focus on .NET & Java Ecosystems: Continued research and discovery of vulnerabilities in .NET (ViewState, BinaryFormatter) and Java (various libraries, RMI, JNDI) remain significant areas of concern [25][57][58][59][60][29][74][16][17].
Where to Go Deeper
For practitioners seeking to deepen their understanding and practical skills in defending against deserialization attacks, several resources offer invaluable insights:
- OWASP Deserialization Cheat Sheet: An authoritative resource providing guidance on identifying, preventing, and mitigating deserialization vulnerabilities across various languages [24][17].
- Payload Generation Tools: Experimenting with tools like
ysoserial,ysoserial.net,phpggc, andjexbossis crucial for understanding how exploit payloads are constructed. This hands-on experience is vital for both offense and defense [18][31][33][52][16]. - PortSwigger Web Security Academy: Offers practical labs and tutorials specifically focused on exploiting and understanding deserialization vulnerabilities in PHP, Ruby, and Java [43][13][80].
- Vendor Security Advisories and Blogs: Regularly consulting advisories from vendors like Cisco, IBM, Microsoft, SAP, and others, as well as security research blogs (Bishop Fox, Snyk, SentinelOne, etc.), provides insights into current threats and attack vectors [25][53][55][57][58][59][60][66][67][75][68][78][29][74].
- Academic Research Papers: Publications in security conferences (e.g., USENIX Security) offer deep dives into novel detection techniques, gadget discovery algorithms, and analysis of deserialization surfaces [50][85][70][82][86][11][76].
- Technical Write-ups and Blog Posts: Numerous blog posts dissect specific vulnerabilities, provide detailed exploit walkthroughs, and discuss mitigation strategies. Examples include those from Bishop Fox, SentinelOne, Medium contributors, and academic institutions [25][57][50][46][8][65][66][70][67][23][40][41][35][72][21][68][78][29][74][12][22].
- GitHub Repositories: Projects like
PayloadsAllTheThings,ysoserial,ysoserial.net, and various research repositories offer code examples, payloads, and tools for practical study [26][19][39][18][31][33][27][52][16].