Back to Glossary
What is Insecure Deserialization?
Definition
A vulnerability where an application deserializes untrusted data without validation, allowing attackers to manipulate serialized objects to execute arbitrary code.
Security Impact
Remote Code Execution (RCE), authentication bypass, and denial of service. Particularly dangerous in Java (ObjectInputStream) and PHP (unserialize).
How to Remediate
Never deserialize untrusted input, use data formats like JSON instead of native serialization, implement integrity checks (HMAC), and apply strict type constraints.
Want to automatically detect and block Insecure Deserialization vulnerabilities in your CI/CD pipeline?
Start scanning with Bryxe