Serialization Security Review
Purpose
Find vulnerabilities caused by unsafe serialization, deserialization, object mapping, parser configuration, and cross-boundary state transfer. Focus on cases where untrusted bytes, JSON, YAML, XML, cookies, view state, cache blobs, or queue messages are turned into executable, privileged, or overly dynamic objects.
High-Risk Targets
Prioritize:
- Java native serialization and
ObjectInputStream - Jackson polymorphic typing and unsafe default ty
[Description truncada. Veja o README completo no GitHub.]