Deserialization is the process of turning stored or transmitted data back into program objects; when it is applied to untrusted input, it can let attackers execute code.
How deserialization attacks work
Applications serialize objects – convert them into bytes, JSON or XML – to save them or send them over the network, and deserialize them on the other side. Formats such as Java serialization, .NET BinaryFormatter, PHP unserialize() or Python pickle can recreate arbitrary object types and automatically call some of their methods. An attacker who controls the serialized data can chain existing classes in the application’s libraries (“gadget chains”) so that recreating the objects runs commands. Tools such as ysoserial generate such payloads automatically.
The weakness is catalogued as CWE-502 (“Deserialization of Untrusted Data”). Research published in 2015 on gadget chains in the Apache Commons Collections library showed that many Java applications, including Jenkins and Oracle WebLogic, were exploitable this way.
Why it matters
Insecure deserialization usually leads to remote code execution, often without authentication, which puts these vulnerabilities at the top of severity scales. Enterprise middleware, VPN appliances and file-transfer products have repeatedly been hacked through deserialization bugs, and public exploits appear quickly. Related to code injection, it is part of the OWASP Top 10 category “Software and Data Integrity Failures”.
How to prevent it
- Do not deserialize data from untrusted sources with native object formats; use simple data formats such as JSON with strict schemas.
- If native deserialization is unavoidable, use allowlists of permitted classes and integrity checks (signatures).
- Remove unused libraries that provide gadget chains and keep frameworks updated.
- Monitor for deserialization exceptions and unusual child processes.