Weaknesses of type CWE-502

2,669 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-0859MEDIUMTYPO3 CMS Allows Insecure Deserialization via Mailer File SpoolEPSS 0.2%CVE-2025-11739HIGHCWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges wheEPSS 0.2%CVE-2025-40759HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP EPSS 0.2%CVE-2025-46738MEDIUMDeserialization of Untrusted DataEPSS 0.2%CVE-2025-30025MEDIUMThe communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalatioEPSS 0.2%CVE-2025-31935MEDIUMSubnet Solutions PowerSYSTEM Center Deserialization of Untrusted DataEPSS 0.2%CVE-2025-2180MEDIUMCheckov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code ExecutionEPSS 0.2%CVE-2022-1984MEDIUMThis issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versiEPSS 0.2%CVE-2023-32737HIGHA vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do not properly restriEPSS 0.2%CVE-2025-48535HIGHIn assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a lauEPSS 0.2%CVE-2026-24237HIGHNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of EPSS 0.2%CVE-2025-4393MEDIUMMedtronic MyCareLink Patient Monitor Deserialization VulnerabilityEPSS 0.2%CVE-2024-54678HIGHA vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All vEPSS 0.2%CVE-2026-24221HIGHNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of EPSS 0.2%CVE-2025-41701HIGHBeckhoff: Deserialization of untrusted data by TwinCAT 3 EngineeringEPSS 0.2%CVE-2025-61677LOWDataChain: Deserialization of Untrusted Data from Environment VariablesEPSS 0.2%CVE-2026-24228HIGHNVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploitEPSS 0.2%CVE-2025-48018HIGHDeserialization of Untrusted DataEPSS 0.2%CVE-2025-41700HIGHCODESYS Development System - Deserialization of Untrusted DataEPSS 0.2%CVE-2024-10382HIGHArbitrary Code execution in Car App Android Jetpack LibraryEPSS 0.2%