FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

deserialization-vulnerability · GitHub Topics · GitHub

#

deserialization-vulnerability

Here are 29 public repositories matching this topic...

Fastjson扫描器,可识别版本、依赖库、autoType状态等。A tool to distinguish fastjson ,version and dependency

  • Updated Oct 7, 2022
  • Go

Java反序列化/JNDI注入/恶意类生成工具,支持多种高版本bypass,支持回显/内存马等多种扩展利用。

  • Updated Apr 8, 2026
  • Java

Peas create serialized payload for deserialization RCE attack on python driven applications where pickle ,pyYAML, ruamel.yaml or jsonpickle module is used for deserialization of serialized data. I will update it with more attack vectors to targets other modules.

  • Updated Nov 25, 2023
  • Python

Everything I needed to understand what was going on with "Spring4Shell" - translated source materials, exploit, links to demo apps, and more.

  • Updated Apr 5, 2022
  • Python

GPT AiCSA(Code security audit),SAST(Static Application Security Testing,静态应用程序安全测试),JAR security analysis, static vulnerability and vulnerability analysis of various programming language codes

  • Updated Dec 26, 2023
  • JavaScript

Vulnerable webapp testbed

  • Updated May 11, 2016
  • Java

GadgetExplorer is a .NET command-line tool for finding potential deserialization gadget chains in managed applications. It scans one or more assemblies, builds a reachability graph with dispatch and callback heuristics, and reports when a deserialization entrypoint can reach a sink you care about.

  • Updated May 22, 2026
  • C#

[FSE'26] GadgetHunter: Region-Based Neuro-symbolic Detection of Java Deserialization Vulnerabilities

  • Updated Aug 3, 2026
  • Python

A JBoss Byteman rule to debug the trace the JDK deserialization filtering

  • Updated Aug 28, 2026
  • JavaScript

PoC for CVE-2020-28032 (It's just a POP chain in WordPress < 5.5.2 for exploiting PHP Object Injection)

  • Updated Nov 17, 2021
  • PHP

Python Deserialization Payload Generator

  • Updated Mar 15, 2020
  • Python

Ruby Deserialization Payload Generator

  • Updated Mar 8, 2020
  • Ruby

maptool unauthenticated rce exploit <1.8.0 beta2b

  • Updated Feb 10, 2021
  • Python

Fake MySQL Server for Exploit Vulnerability of MySQL JDBC Driver

  • Updated Jun 9, 2023
  • Java

Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

  • Updated Nov 20, 2025
  • Python

This project contains a Java deserialization vulnerability that is exploitable with some ysoserial payloads, but also contains a custom class that can be leveraged to get command execution upon deserialization.

  • Updated Aug 8, 2022
  • Java

Improve this page

Add a description, image, and links to the deserialization-vulnerability topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the deserialization-vulnerability topic, visit your repo's landing page and select "manage topics."

Learn more


Back | FazBrowse Home | New Git URL