A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40711.json"
[ { "events": [ { "introduced": "12.0.0.1420" }, { "fixed": "12.2.0.334" } ] } ]