Skip to content

Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unserialize()

High severity GitHub Reviewed Published Feb 19, 2026 in zumba/json-serializer • Updated Feb 23, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts