Loading vulnerability details…
CVSS v3.1
N/A
CVSS v4.0
5.3
EPSS
0.32%
Published
Jun 10, 2026
Modified
Jun 10, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution.
Weaknesses (CWE)
References (1)