Crystallizer: A Hybrid Path Analysis Framework to Aid in Uncovering Deserialization Vulnerabilities
Prashast Srivastava, Flavio Toffalini, Kostyantyn Vorobyov, François Gauthier, Antonio Bianchi, Mathias Payer
Abstract
Applications use serialization and deserialization to exchange data. Serialization allows developers to exchange messages or perform remote method invocation in distributed applications. However, the application logic itself is responsible for security. Adversaries may abuse bugs in the deserialization logic to forcibly invoke attackercontrolled methods by crafting malicious bytestreams (payloads).
Crystallizer presents a novel hybrid framework to automatically uncover deserialization vulnerabilities by combining static and dynamic analyses. Our intuition is to first over-approximate possible payloads through static analysis (to constrain the search space). Then, we use dynamic analysis to instantiate concrete payloads as a proof-of-concept of a vulnerability (giving the analyst concrete examples of possible attacks). Our proof-of-concept focuses on Java deserialization as the imminent domain of such attacks.
We evaluate our prototype on seven popular Java libraries against state-of-the-art frameworks for uncovering gadget chains. In contrast to existing tools, we uncovered 41 previously unknown exploitable chains. Furthermore, we show the real-world security impact of Crystallizer by using it to synthesize gadget chains to mount RCE and DoS attacks on three popular Java applications. We have responsibly disclosed all newly discovered vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 51289ac2-e831-46c5-b448-2ecdc2a16c12Cited by top-tier papers6
- Gleipner: A Benchmark for Gadget Chain Detection in Java Deserialization VulnerabilitiesBruno Kreyssig, Alexandre BartelFSE 2025 · 2 citations
- The First Large-Scale Systematic Study of Python Class Pollution VulnerabilityZhengyu Liu, Jiacheng Zhong, Jianjia Yu, Muxi Lyu et al.S&P 2026
- Sleeping Giants - Activating Dormant Java Deserialization Gadget Chains through Stealthy Code ChangesBruno Kreyssig, Sabine Houy, Timothée Riom, Alexandre BartelCCS 2025
- Towards Automatic Detection and Exploitation of Java Web Application Vulnerabilities via Concolic Execution guided by Cross-thread Object ManipulationXinyou Huang, Lei Zhang, Yongheng Liu, Peng Deng et al.USENIX Security 2025
- Hercules Droidot and the murder on the JNI ExpressLuca Di Bartolomeo, Philipp Mao, Yu-Jye Tung, Jessy Ayala et al.USENIX Security 2025
Builds on4
- Improving Java Deserialization Gadget Chain Mining via Overriding-Guided Object GenerationSicong Cao, Xiaobing Sun, Xiaoxue Wu, Lili Bo et al.ICSE 2023 · 24 citations
- ODDFuzz: Discovering Java Deserialization Vulnerabilities via Structure-Aware Directed Greybox FuzzingSicong Cao, Biao He, Xiaobing Sun, Yu Ouyang et al.S&P 2023
- FUGIO: Automatic Exploit Generation for PHP Object Injection VulnerabilitiesSunnyeo Park, Daejun Kim, Suman Jana, Sooel SonUSENIX Security 2022
- SerialDetector: Principled and Practical Exploration of Object Injection Vulnerabilities for the WebMikhail Shcherbakov, Musard BalliuNDSS 2021
Related papers
- Precise and Effective Gadget Chain Mining through Deserialization Guided Call Graph ConstructionYiheng Zhang, Ming Wen, Shunjie Liu, Dongjie He et al.USENIX Security 2025
- Efficient Detection of Java Deserialization Gadget Chains via Bottom-up Gadget Search and Dataflow-aided Payload ConstructionBofei Chen, Lei Zhang, Xinyou Huang, Yinzhi Cao et al.S&P 2024 · 12 citations
- GadgetHunter: Region-Based Neuro-symbolic Detection of Java Deserialization VulnerabilitiesKaixuan Li, Jian Zhang, Chong Wang, Sen Chen et al.FSE 2026
- Automatic Policy Synthesis and Enforcement for Protecting Untrusted DeserializationQuan Zhang, Yiwen Xu, Zijing Yin, Chijin Zhou et al.NDSS 2024
- QUACK: Hindering Deserialization Attacks via Static Duck TypingYaniv David, Neophytos Christou, Andreas D. Kellas, Vasileios P. Kemerlis et al.NDSS 2024
