CVE-2021-20190
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The hig
CVSS
8.1
High
EPSS
7.5%
p94
KEV
—
Exploit Today
28
0-100
Published: Jan 19, 2021 · Last modified: Jul 24, 2026 · CWE-502
7.5%EPSS · 30 days7.5%
2026-07-052026-08-01
A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=1916633
- github.comhttps://github.com/FasterXML/jackson-databind/issues/2854
- lists.apache.orghttps://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a%40%3Ccommits.nifi.apache.org%3E
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2021/04/msg00025.html
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20210219-0008/
- www.oracle.comhttps://www.oracle.com//security-alerts/cpujul2021.html
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=1916633
- github.comhttps://github.com/FasterXML/jackson-databind/issues/2854
- lists.apache.orghttps://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a%40%3Ccommits.nifi.apache.org%3E
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2021/04/msg00025.html
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20210219-0008/
- www.oracle.comhttps://www.oracle.com//security-alerts/cpujul2021.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-32457.5 HIG—
———A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.7hCVE-2026-687719.8 CRI46.5%
——14ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.2dCVE-2026-127207.5 HIG22.8%
——7The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress version), this could be leveraged to perform a variety of attacks, such as remote code execution.3dCVE-2026-115368.5 HIG26.3%
——8IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.3dCVE-2026-159769.8 CRI25.8%
——8SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.2dCVE-2026-159699.8 CRI58.8%
——18SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.3d