DevExpress.XtraReports.UI through v21.1 allows malicious users to execute arbitrary code via insecure deserialization.
devexpress devexpress