CVE-2020-24164: Taoensso Nippy

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.

Affected products

  • Taoensso Nippy: before 2.14.2 (fixed in 2.14.2)

Published 2020-09-11. Last modified 2026-06-17.