CWE-502
Overview
- CWE ID
- 502
- CWE Name
- Deserialization of Untrusted Data
- CWE Abstraction
- Base
- CWE structure
- Simple
- CWE Status
- Draft
Description
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.