Weaknesses of type CWE-502

2,669 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-55136MEDIUMERC (aka Emotion Recognition in Conversation) through 0.3 has insecure deserialization via a serialized object because jsonpickle is used.EPSS 0.2%CVE-2025-70560HIGHBoltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to EPSS 0.2%CVE-2023-3360LOWWeaver Show Posts < 1.8.1 - Admin+ PHP Object InjectionEPSS 0.1%CVE-2024-0047MEDIUMIn writeUserLP of UserManagerService.java, device policies are serialized with an incorrect tag due to a logic error in the code. This couldEPSS 0.1%CVE-2026-10721HIGHConcrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search componentsEPSS 0.1%CVE-2026-0895MEDIUMInsecure Deserialization in extension "Mailqueue" (mailqueue)EPSS 0.1%CVE-2026-17156HIGHIBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEsEPSS 0.1%CVE-2026-17416HIGHIBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEsEPSS 0.1%CVE-2026-12191HIGHComma AI Openpilot Pickle modeld.py pickle.loads deserializationEPSS 0.1%CVE-2026-100845HIGHMONAI before 1.6.0 Remote Code Execution via NumpyReaderEPSS 0.1%CVE-2026-23685MEDIUMInsecure Deserialization vulnerability in SAP NetWeaver (JMS service)EPSS 0.1%CVE-2024-39673MEDIUMVulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affeEPSS 0.1%CVE-2026-100841HIGHMONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle CacheEPSS 0.1%CVE-2024-8375MEDIUMObject deserialization in Reverb leading to RCEEPSS 0.1%CVE-2026-10566MEDIUMFoundationAgents MetaGPT schema.py Message.check_instruct_content deserializationEPSS 0.1%CVE-2024-43080HIGHIn onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to EPSS 0.1%CVE-2025-8747HIGHKeras safe_mode bypass allows arbitrary code execution when loading a malicious model.EPSS 0.1%CVE-2024-8885HIGHA local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writinEPSS 0.1%CVE-2022-32601HIGHIn telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation of privilege with nEPSS 0.1%CVE-2026-19795MEDIUMQiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space.EPSS 0.1%