https://phpunserialize.com/
PHP Unserialize Online
A simple tool to unserialize PHP data
phpunserializeonline
https://bugs.php.net/bug.php?id=72584
PHP :: Bug #72584 :: Exception::__toString() fails after unserialize().
phpbugexceptiontostringfails
https://unserialize.dev/
Unserialize - Convert your serialized data into a readable format
Unserialize your PHP serialized data into a readable format like JSON or an Array quickly and easily with the PHP unserialize function.
unserializeconvertserializeddatareadable
https://bugs.php.net/bug.php?id=70168
PHP :: Sec Bug #70168 :: Use After Free Vulnerability in unserialize() with SplObjectStorage
https://www.php.net/manual/tr/gmp.unserialize.php
PHP: GMP::__unserialize - Manual
Deserializes the data parameter into a GMP object
phpgmpunserializemanual
https://advisories.gitlab.com/composer/typo3/flow/GHSA-m2hp-5x78-74mg/
Insecure Unserialize Vulnerability in FLOW3 | GitLab Advisory Database (GLAD)
GHSA-m2hp-5x78-74mg Insecure Unserialize Vulnerability in FLOW3: Due to a missing signature (HMAC) for a request argument, an attacker could unserialize...
insecureunserializevulnerabilitygitlabadvisory
https://bugs.php.net/bug.php?id=68044&edit=1
PHP :: Sec Bug #68044 :: Integer overflow in unserialize() (32-bits only)
integer overflowphpsecbug
https://bugs.php.net/bug.php?id=10863&edit=1
PHP :: Request #10863 :: serialize/unserialize doesn't handle references
t handlephprequestserializereferences
https://www.php.net/manual/uk/splfixedarray.unserialize.php
PHP: SplFixedArray::__unserialize - Manual
Deserializes the data parameter into an SplFixedArray object
phpunserializemanual
https://www.php.net/manual/en/serializable.unserialize.php?ref=jus.tin.sg
PHP: Serializable::unserialize - Manual
Constructs the object
phpserializableunserializemanual
https://bugs.php.net/bug.php?id=60879
PHP :: Bug #60879 :: unserialize() Does not invoke __wakeup() on object
does notphpbugunserializeinvoke
https://advisories.gitlab.com/composer/typo3/cms/GHSA-xvcp-33rc-j8gq/
Insecure Unserialize in TYPO3 Import/Export | GitLab Advisory Database (GLAD)
GHSA-xvcp-33rc-j8gq Insecure Unserialize in TYPO3 Import/Export: Failing to properly validate incoming import data, the Import/Export component is susceptible...
import exportinsecureunserializegitlabadvisory
https://bugs.php.net/bug.php?id=77283
PHP :: Bug #77283 :: memory exhausted when unserialize data
phpbugmemoryexhaustedunserialize
https://www.php.net/manual/ja/arrayiterator.unserialize.php
PHP: ArrayIterator::unserialize - Manual
phpunserializemanual
https://bugs.php.net/bug.php?id=79002
PHP :: Bug #79002 :: Serializing uninitialized typed properties with __sleep makes unserialize throw
https://www.php.net/manual/uk/arrayobject.unserialize.php
PHP: ArrayObject::unserialize - Manual
Unserialize an ArrayObject
phpunserializemanual
https://www.drupal.org/node/3181275
Do not register Phar stream wrapper on PHP 8 because it is not vulnerable to unserialize bugs...
Feb 8, 2022 - Problem/Motivation Once we update in [#3181240] then PHP 8 doesn't have the same vulnerability as PHP 7 so there's no need to register the phar stream wrapper.
https://bugs.php.net/bug.php?id=73092
PHP :: Sec Bug #73092 :: Unserialize use-after-free when resizing object's properties hash table
https://bugs.php.net/bug.php?id=12497
PHP :: Bug #12497 :: Problem with serialize/unserialize
phpbugproblemserialize
https://www.php.net/manual/it/solrdocument.unserialize.php
PHP: SolrDocument::unserialize - Manual
Custom serialization of SolrDocument objects
phpunserializemanual
https://bugs.php.net/bug.php?id=74101&edit=2
PHP :: Sec Bug #74101 :: Unserialize Heap Use-After-Free (READ: 1) in zval_get_type
https://www.php.net/manual/ja/solrdocument.unserialize.php
PHP: SolrDocument::unserialize - Manual
Custom serialization of SolrDocument objects
phpunserializemanual
https://bugs.php.net/bug.php?id=70436&edit=2
PHP :: Sec Bug #70436 :: Use After Free Vulnerability in unserialize()
phpsecbugusefree
https://www.php.net/manual/it/random-engine-mt19937.unserialize.php
PHP: Random\Engine\Mt19937::__unserialize - Manual
Deserializes the data parameter into a Mt19937 object
phprandomengineunserializemanual
https://wiki.php.net/rfc/unserialize_warn_on_trailing_data
PHP: rfc:unserialize_warn_on_trailing_data
phprfcunserializewarntrailing
https://advisories.gitlab.com/composer/getgrav/grav/GHSA-vj3m-2g9h-vm4p/
Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI...
GHSA-vj3m-2g9h-vm4p Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypass: Multiple RCE vectors were...
https://www.php.net/manual/uk/datetime.unserialize.php
PHP: DateTime::__unserialize - Manual
Unserialize an Datetime
phpdatetimeunserializemanual
https://www.php.net/manual/pt_BR/spldoublylinkedlist.unserialize.php
PHP: SplDoublyLinkedList::unserialize - Manual
Deserializa o armazenamento
phpunserializemanual
https://www.php.net/manual/de/bcmath-number.unserialize.php
PHP: BcMath\Number::__unserialize - Manual
Deserializes a data parameter into a BcMath\Number object
phpbcmathnumberunserializemanual
https://bugs.php.net/bug.php?id=68545&edit=2
PHP :: Sec Bug #68545 :: NULL pointer dereference in unserialize.c:var_push_dtor
https://www.php.net/manual/es/gmp.unserialize.php
PHP: GMP::__unserialize - Manual
Deserializa el argumento data en un objeto GMP
phpgmpunserializemanual
https://www.php.net/datetime.unserialize
PHP: DateTime::__unserialize - Manual
Unserialize an Datetime
phpdatetimeunserializemanual
https://media.ccc.de/v/33c3-7858-exploiting_php7_unserialize
Exploiting PHP7 unserialize - media.ccc.de
PHP-7 is a new version of the most prevalent server-side language in use today. Like previous version, this version is also vulnerable to...
exploitingunserializemediacccde
https://www.php.net/manual/uk/random-engine-pcgoneseq128xslrr64.unserialize.php
PHP: Random\Engine\PcgOneseq128XslRr64::__unserialize - Manual
Deserializes the data parameter into a PcgOneseq128XslRr64 object
phprandomengineunserializemanual
https://bugs.php.net/bug.php?id=73832
PHP :: Sec Bug #73832 :: Use of uninitialized memory in unserialize()
phpsecbugusememory
https://www.php.net/manual/es/random-engine-xoshiro256starstar.unserialize.php
PHP: Random\Engine\Xoshiro256StarStar::__unserialize - Manual
Deserializa el argumento data en un objeto Xoshiro256StarStar
phprandomengineunserializemanual
https://www.php.net/manual/zh/function.igbinary-unserialize.php
PHP: igbinary_unserialize - Manual
Creates a PHP value from a stored representation from igbinary_serialize
phpunserializemanual
https://bugs.php.net/bug.php?id=68044&edit=2
PHP :: Sec Bug #68044 :: Integer overflow in unserialize() (32-bits only)
integer overflowphpsecbug
https://bugs.php.net/bug.php?id=68594&edit=2
PHP :: Sec Bug #68594 :: Use after free vulnerability in unserialize()
phpsecbugusefree
https://www.php.net/igbinary-unserialize
PHP: igbinary_unserialize - Manual
Creates a PHP value from a stored representation from igbinary_serialize
phpunserializemanual
https://www.php.net/manual/zh/gmp.unserialize.php
PHP: GMP::__unserialize - Manual
Deserializes the data parameter into a GMP object
phpgmpunserializemanual
https://www.php.net/manual/en/gmp.unserialize.php
PHP: GMP::__unserialize - Manual
Deserializes the data parameter into a GMP object
phpgmpunserializemanual
https://bugs.php.net/bug.php?id=31169&edit=1
PHP :: Bug #31169 :: unserialize is broken
phpbugunserializebroken
https://www.php.net/manual/pt_BR/datetime.unserialize.php
PHP: DateTime::__unserialize - Manual
Desserializa um Datetime
phpdatetimeunserializemanual