package bench.reachability; import java.util.Map; import java.util.Base64; import java.io.*; public class App { // Unsafe Java deserialization sink (reachable) public static Response handleRequest(Map body) { String payload = body.get("payload"); if (payload == null) { return new Response(400, "bad request"); } try { byte[] data = Base64.getDecoder().decode(payload); ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(data)); Object obj = ois.readObject(); ois.close(); return new Response(200, obj.toString()); } catch (Exception ex) { return new Response(500, ex.getClass().getSimpleName()); } } public record Response(int status, String body) {} }