Weaknesses of type CWE-502

2,669 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-53415HIGHFile Parsing Deserialization of Untrusted Data in DTM SoftEPSS 0.2%CVE-2026-2626HIGHDivi Booster < 5.0.2 - Unauthenticated PHP Object InjectionEPSS 0.2%CVE-2025-33241HIGHNVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A EPSS 0.2%CVE-2025-33243HIGHNVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successfulEPSS 0.2%CVE-2024-10013HIGHProgress UI for WinForms format provider unsafe deserialization vulnerabilityEPSS 0.2%CVE-2025-33226HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A sEPSS 0.2%CVE-2025-54886HIGHskops: Card.get_model does not block arbitrary code executionEPSS 0.2%CVE-2023-32736HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16EPSS 0.2%CVE-2024-34274LOWOpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD softEPSS 0.2%CVE-2024-49849HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16EPSS 0.2%CVE-2026-1323MEDIUMInsecure Deserialization in extension "Mailqueue" (mailqueue)EPSS 0.2%CVE-2025-7976HIGHAnritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-36471MEDIUMDeserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbiEPSS 0.2%CVE-2023-32735HIGHA vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V1EPSS 0.2%CVE-2026-24141HIGHNVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deseEPSS 0.2%CVE-2026-24150HIGHNVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciouEPSS 0.2%CVE-2025-33248HIGHNVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load EPSS 0.2%CVE-2026-24152HIGHNVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciouEPSS 0.2%CVE-2026-24151HIGHNVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously craEPSS 0.2%CVE-2025-53393MEDIUMIn Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.EPSS 0.2%