Deserialization Gadget Scan
deserialization-gadget-scan is a critical severity check in the
web category, written in java.
Its source is templates/web/deserialization/DeserializationGadgetScan.java in
cert-x-gen-templates.
What it checks
Section titled “What it checks”Detects Java deserialization attack surfaces by probing TCP services for Java serialization magic bytes, fingerprinting exposed gadget chain libraries (CommonsCollections, Spring Beans, Groovy, etc.) via class descriptor leakage and exception analysis. Does NOT send exploit payloads.
Header
Section titled “Header”| Field | Value |
|---|---|
| Id | deserialization-gadget-scan |
| Severity | critical |
| Language | java |
| Category | web |
| Author | CERT-X-GEN Security Team |
| Template version | not recorded |
| Confidence | 90 |
| CVSS | not recorded |
| Weakness | CWE-502 |
| Tags | java, deserialization, ysoserial, gadget-chain, rce, commons-collections, jmx, rmi, jboss |
| Target kind | not recorded |
| Oracle | not recorded |
References
Section titled “References”Declared in the header. cxg parses @references and then discards it, and
nothing at scan time reads it, so this is the only place the links a
template cites are surfaced.
- https://nvd.nist.gov/vuln/detail/CVE-2015-4852
- https://github.com/frohoff/ysoserial
- https://owasp.org/www-community/vulnerabilities/Deserialization_of_untrusted_data
Run it
Section titled “Run it”To see what the copy on your machine says about itself, and to confirm it is installed at all:
cxg template info deserialization-gadget-scanThe id it prints is the one to pass anywhere a template is selected. See
cxg template for the rest of
the subcommand, Scan a target for running
a scan, and
A match is not a finding for how
to read what comes back.
Related
Section titled “Related”- Template catalog is the whole corpus.
- web is the rest of this category.
- Templates by weakness class groups checks by the defect they look for.
- Contribute a template is the route from a check you needed and could not find to a merged one.

