In Corda before 4.1, the meaning of serialized data can be modified via an attacker-controlled CustomSerializer.Referenceshttps://docs.r3.com/en/platform/corda/4.1/open-source/release-notes.html