WhisperX tag archive

#Deserialization Vulnerability

This page collects WhisperX intelligence signals tagged #Deserialization Vulnerability. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-02 13:27:26 · GitHub Issues

1. High-Severity Jackson Databind Flaw (CVE-2022-42004) Exposes Widespread Software Supply Chain Risk

A high-severity deserialization vulnerability, CVE-2022-42004, has been detected across multiple versions of the ubiquitous Jackson Databind library, exposing a critical software supply chain risk. The flaw, present in versions including 2.13.2.2, 2.12.4, and several legacy 2.9.x releases, allows for potential remote c...

The Lab · 2026-04-20 22:23:01 · GitHub Issues

2. Apache Log4j Critical RCE Flaw CVE-2017-5645: Deserialization Vulnerability in Socket Servers

A critical deserialization vulnerability in Apache Log4j 2.x, tracked as CVE-2017-5645, exposes systems to remote code execution (RCE) attacks. With a maximum CVSS severity score of 9.8, the flaw resides in the TCP and UDP socket server components. When these servers are used to receive serialized log events, a malicio...

The Lab · 2026-04-28 12:54:11 · GitHub Issues

3. React Server Components Flaw Enables Denial-of-Service Attacks on 19.2.x Deployments

A critical vulnerability in React's Server Components architecture exposes applications running version 19.2.0 through 19.2.4 to denial-of-service conditions. Tracked as CVE-2026-23869 with a CVSS score of 7.5, the flaw resides in the `react-server-dom-webpack` package—a component bundled with React 19.2.x that handles...