Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Security Intel Hub 407— Search: 反序列化×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
Jenkins Plugin Security Advisory: RCE, SSRF, AFR, Path Traversal via CVEs
www.jenkins.io · 2026-05-28

### Jenkins Security Advisory 2026-05-27 #### Vulnerability Summary 1. **RCE via Unvalidated LDAP Redirect in LDAP Plugin** - **CVE**: CVE-2026-48916 (SSRF), CVE-2026-48917 (Deserialization) - **Sever…

Read more
Jenkins Plugin Security Bulletin: RCE, SSRF, LFI via LDAP/AD/Credentials
www.jenkins.io · 2026-05-28

### Jenkins Security Advisory 2026-05-27 #### Vulnerability Overview This advisory announces vulnerabilities in the following Jenkins components: - Active Directory Plugin - AppSpider Plugin - Bitbuck…

Read more
Jenkins Security Advisory: RCE and Path Traversal in Multiple Plugins (CVE-2026-48916-48925)
www.jenkins.io · 2026-05-28

### Jenkins Security Advisory 2026-05-27 #### Vulnerability Overview This advisory announces vulnerabilities in the following Jenkins components: 1. **Remote Code Execution (RCE) Vulnerability in LDAP…

Read more
Jenkins Plugin Advisory: LDAP Redirection Leads to RCE via Deserialization
www.jenkins.io · 2026-05-28

### Jenkins Security Advisory 2026-05-27 #### Vulnerability Overview This advisory announces vulnerabilities in the following Jenkins artifacts: - Active Directory Plugin - AppSpider Plugin - Bitbucke…

Read more
Jenkins Security Bulletin: Multiple Plugin Vulnerabilities including RCE, AFR, CSRF
www.jenkins.io · 2026-05-28

### Jenkins Security Advisory 2026-05-27 Vulnerability Summary #### Vulnerability Overview 1. **RCE vulnerability due to unvalidated LDAP redirection in the LDAP Plugin** - **CVE**: CVE-2026-48916 (SS…

Read more
Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection | Advisories | Vul
www.vulncheck.com · 2026-06-13

### Vulnerability Overview A vulnerability exists in Ghidra versions prior to 12.1 involving unfiltered RMI deserialization. Attackers can exploit this by crafting a malicious shared project connectio…

Read more
Apache Storm 2.x RCE (CVE-2026-35337) and Stored XSS (CVE-2026-35565) Advisory
storm.apache.org · 2026-04-18

### Vulnerability Overview #### CVE-2026-35337 - Untrusted Data Deserialization Vulnerability - **Description**: When processing topology credentials submitted via the Nimbus Thrift API, Storm deseria…

Read more
CVE-2026-31223 | Notion
www.notion.so · 2026-05-22

# CVE-2026-31223 Vulnerability Summary ## Vulnerability Overview - **Vulnerability ID**: CVE-2026-31223 - **Vulnerability Type**: Unsafe Deserialization (CWE-502) - **Affected Component**: `BaseLabele…

Read more
CVE Record: CVE-2026-24142
www.cve.org · 2026-05-22

# CVE-2026-24142 Vulnerability Summary ## Vulnerability Overview * **Vulnerability ID**: CVE-2026-24142 * **Vulnerability Type**: Deserialization Vulnerability * **Severity**: Medium (CVSS Score: 6.3)…

Read more
Jenkins Security Bulletin: Deserialization, XSS, Auth Bypass (CVE-2026-53435) Patch Guide
www.jenkins.io · 2026-06-13

### Jenkins Security Advisory 2026-06-10 #### Vulnerability Overview 1. **Deserialization Vulnerability** - **CVE**: CVE-2026-53435 - **Severity**: High - **Description**: Jenkins uses serialization a…

Read more
CVE-2026-40993: Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry
spring.io · 2026-06-13

# CVE-2026-40993: Unsanitized Java Native Deserialization SAML 2.0 Asserting Party Credentials Blob Database Entries ## Vulnerability Overview An attacker can store a malicious serialized payload in t…

Read more
Jenkins Security Advisory 2026-06-10
www.jenkins.io · 2026-06-10

### Jenkins Security Advisory 2026-06-10 #### Vulnerability Overview 1. **Deserialization Vulnerability** - **CVE**: CVE-2026-53435 - **Severity**: High - **Description**: Jenkins uses serialization a…

Read more
Keras TFSMLayer Bypasses safe_mode Leading to RCE (CVE-2026-1462)
huntr.com · 2026-04-18

# TFSMLayer Bypass `safe_mode=True` Vulnerability Summary ## Vulnerability Overview **CVE-2026-1462** **Severity**: High (8.8) **Affected Component**: `keras-team/keras` (TFSMLayer class) **Core Issue…

Read more
CVSS 5.3
Blockchain Node DoS Fix: Malicious HistoricTransaction Triggers Panic in History Sync
github.com · 2026-04-23

# Vulnerability Summary ## Overview - **Vulnerability Name**: Fix panic triggered by sync node during historical synchronization. - **Description**: A malicious sync node can cause the sync node to cr…

Read more
www.wordfence.com · 2026-05-05

# Vulnerability Overview **Vulnerability Name**: Apache ActiveMQ Remote Code Execution Vulnerability (CVE-2023-46697) **Vulnerability Description**: Apache ActiveMQ is an open-source message broker an…

Read more
Ray Multiple Components Vulnerability Fix Advisory (RCE/Serialization)
github.com · 2026-05-09

### Vulnerability Summary #### Overview - **Vulnerability Name**: Vulnerabilities Fixed in Multiple Components - **Affected Components**: Ray Data, Ray Serve, Ray Train, Ray Tune, Ray LLM, Ray RLlib, …

Read more
9.5.1 Release Notes :: Concrete CMS
documentation.concretecms.org · 2026-05-22

# Concrete CMS 9.5.1 Security Vulnerability Summary ## Vulnerability Overview Concrete CMS version 9.5.1 addresses multiple critical security vulnerabilities, including: - **Remote Code Execution (RCE…

Read more
CVSS 5.3
Contao Controller.php Variable Reference Fix
github.com · 2025-08-30

From this webpage screenshot, the following key vulnerability-related information can be extracted: - **Submission Details**: - Submission ID: a03976c - Submitter: fritzmg - Submission Time: Yesterday…

Read more
RHSA-2018:0294: Red Hat JBoss Data Grid 7.1.2 Security Update (CVE-2017-7525/15089/9970)
access.redhat.com · 2025-11-10

## Critical Vulnerability Information **Overview** - **Advisory ID:** RHSA-2018:0294 - **Release Date:** 2018-02-12 - **Update Date:** 2018-02-12 **Type/Severity** - **Severity:** Important **Subject*…

Read more
CVSS 8.6
Arbitrary Code Execution in pdfminer.six via Crafted PDF (CVE-2025-64512)
github.com · 2025-11-11

### Key Information - **Vulnerability Name**: Arbitrary Code Execution in pdfminer.six via Crafted PDF Input - **Severity**: High (8.6 / 10) - **CVE ID**: CVE-2025-64512 #### **Main Issues** - **Affec…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.