High severityC#Insecure DeserializationHIGH confidence
Dangerous Formatters
A type-permissive .NET formatter (NetDataContractSerializer, SoapFormatter, LosFormatter, or ObjectStateFormatter) is used.
Standards mapping
- OWASP Top 10
- A08:2021 - Software and Data Integrity Failures
- OWASP ASVS
- V5.5.3 (L1)
Vulnerable vs. safe
Flagged by this check
return soapFormatter.Deserialize(stream);Passes - the safe pattern
var s = new System.Runtime.Serialization.DataContractSerializer(typeof(string));Why it matters & how to fix it
A type-permissive .NET formatter (NetDataContractSerializer, SoapFormatter, LosFormatter, or ObjectStateFormatter) is used. These embed and instantiate arbitrary CLR types from the payload, enabling deserialization RCE when the input is attacker-controlled (CWE-502). Use System.Text.Json or a DataContractSerializer bound to an explicit, known type set instead.
References
Rule ID integsec.csharp.deserialization.dangerous-formatters - engine: Opengrep - license: MIT - Copyright (c) IntegSec Inc.
TurboPentest runs this check automatically
Connect a GitHub repo and this check runs on every white-box pentest - AI-validated and reported with proof, from $99 per target.
Start a pentestRelated checks
- JavaScript / TypeScript - Insecure DeserializationNode Serialize Unserialize
- JavaScript / TypeScript - Insecure DeserializationYAML Unsafe Load
- Python - Insecure DeserializationJsonpickle Decode
- Python - Insecure DeserializationPickle Load
- Python - Insecure DeserializationYAML Unsafe Load
- Java - Insecure DeserializationJackson Default Typing