Java Signedobject Deserialization

Identify and analyze Java SignedObject-gated deserialization vulnerabilities, including pre-auth reachability via error handlers. Use this skill whenever investigating Java deserialization issues, analyzing stack traces with SignedObject.getObject() calls, reviewing license/authentication endpoints, or assessing applications that use java.security.SignedObject for serialization. Trigger on mentions of SignedObject, Java deserialization, license validation, signature verification, or CVE-2025-10035 patterns.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/pentesting-web/deserialization/java-signedobject-gated-deserialization commit 3e3d4ec4f0

Frequently asked questions

npx skillmds@latest add abelrguezr/java-signedobject-deserialization