Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-60830MEDIUMredragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.EPSS 0.4%CVE-2025-61505MEDIUMe107 CMS thru 2.3.3 are vulnerable to insecure deserialization in the `install.php` script. The script processes user-controlled input in thEPSS 0.4%CVE-2026-22471HIGHWordPress Secudeal Payments for Ecommerce plugin <= 1.1 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-68531HIGHWordPress ModelTheme Addons for WPBakery and Elementor plugin < 1.5.6 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-22345HIGHWordPress Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin <= 1.6.0 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-22346HIGHWordPress Slider Responsive Slideshow – Image slider, Gallery slideshow plugin <= 1.5.4 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2026-25551HIGHSeagull Software BarTender Deserialization Privilege Escalation via .NET Remoting ServiceEPSS 0.4%CVE-2026-23544HIGHWordPress Valenti theme <= 5.6.3.5 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-69328HIGHWordPress Booking and Rental Manager plugin <= 2.5.9 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2024-28964HIGHDell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticatEPSS 0.4%CVE-2026-31250HIGHCosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in EPSS 0.4%CVE-2026-31249HIGHCosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in EPSS 0.4%CVE-2025-15453MEDIUMmilvus HTTP Endpoint expr.go expr.Exec deserializationEPSS 0.4%CVE-2026-5473LOWNASA cFS Pickle pickle.load deserializationEPSS 0.4%CVE-2024-39334MEDIUMMENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a victim opens the deEPSS 0.4%CVE-2025-60080HIGHWordPress PDF for Gravity Forms + Drag And Drop Template Builder plugin <= 6.5.0 - PHP Object Injection vulnerabilityEPSS 0.4%CVE-2025-15276HIGHFontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 0.4%CVE-2022-27579—A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and incEPSS 0.4%CVE-2026-47878MEDIUMUnsafe Java deserialization in DefaultExecutionContextSerializer without class allowlistEPSS 0.4%CVE-2026-35502MEDIUMDeserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow anEPSS 0.4%