Weaknesses of type CWE-502

2,669 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-39577HIGHWordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-24216HIGHNVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of thisEPSS 0.3%CVE-2025-15246MEDIUMaizuda snail-job API FurySerializer.deserialize deserializationEPSS 0.3%CVE-2026-3048MEDIUMNexus Repository 3 - Improper LDAP Referral HandlingEPSS 0.3%CVE-2025-63617MEDIUMktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fasEPSS 0.3%CVE-2023-28072HIGH Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious useEPSS 0.3%CVE-2025-53416HIGHFile Parsing Deserialization of Untrusted Data in DTN SoftEPSS 0.3%CVE-2025-59050HIGHGreenshot — Insecure .NET deserialization via WM_COPYDATA enables local code executionEPSS 0.3%CVE-2025-46567MEDIUMLLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.pyEPSS 0.3%CVE-2025-8871MEDIUMEverest Forms (Pro) <= 1.9.7 - Unauthenticated PHP Object Injection via PHAR Deserialization in Form SignatureEPSS 0.3%CVE-2026-1235MEDIUMWP eCommerce <= 3.15.1 - Unauthenticated PHP Object InjectionEPSS 0.3%CVE-2025-23254HIGHNVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by locaEPSS 0.3%CVE-2025-67747HIGHFickling has missing detection for marshal.loads and types.FunctionType in unsafe modules listEPSS 0.3%CVE-2026-52777CRITICALYesWiki: Authenticated PHP Object Injection in BazarImportAction via unserializeEPSS 0.3%CVE-2026-39324CRITICALRack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationEPSS 0.3%CVE-2026-11857HIGHInsecure .NET Remoting deserialization in Quanos SCHEMA ST4 Client Update Service allows local privilege escalationEPSS 0.3%CVE-2024-0654MEDIUMDeepFaceLab Util.py deserializationEPSS 0.3%CVE-2026-100846HIGHMONAI before 1.5.2 Remote Code Execution via Pickle DeserializationEPSS 0.3%CVE-2026-27410MEDIUMWordPress Slimstat Analytics plugin < 5.4.0 - Deserialization of untrusted data vulnerabilityEPSS 0.3%CVE-2023-51545CRITICALWordPress Job Manager & Career Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF) leading to PHP Object InjectionEPSS 0.3%