Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-65035MEDIUMGLPI Database Inventory Plugin Vulnerable to Stored Object InjectionEPSS 0.3%CVE-2025-3162MEDIUMInternLM LMDeploy PT File utils.py load_weight_ckpt deserializationEPSS 0.3%CVE-2024-32876HIGHNewPipe has potential security vulnerability when importing settingsEPSS 0.3%CVE-2026-10748HIGHNexus Repository 3 - Remote Code Execution via License DeserializationEPSS 0.3%CVE-2026-77092HIGHContent Extractor Privilege EscalationEPSS 0.3%CVE-2026-15531MEDIUMyashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserializationEPSS 0.3%CVE-2025-15117LOWDromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserializationEPSS 0.3%CVE-2026-14723MEDIUMAD-Security AD_Miner Cache analyse_cache.py request_a deserializationEPSS 0.3%CVE-2025-33247HIGHNVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful expEPSS 0.3%CVE-2026-83603HIGHNetdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCEEPSS 0.3%CVE-2026-60412HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version EPSS 0.3%CVE-2026-15555HIGHJboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshallerEPSS 0.3%CVE-2026-56095HIGHInsecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)EPSS 0.3%CVE-2026-60392HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supporteEPSS 0.3%CVE-2026-22248HIGHGLPI affected by Remote Code Execution via malicious uploadEPSS 0.3%CVE-2025-5174MEDIUMerdogant pypickle pypickle.py load deserializationEPSS 0.3%CVE-2026-22384CRITICALWordPress Applay - Shortcodes plugin <= 3.7 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-1286HIGHCWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote cEPSS 0.3%CVE-2023-1145HIGH Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the DeviEPSS 0.3%CVE-2026-47856MEDIUMJsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-listEPSS 0.3%