Weaknesses of type CWE-502

2,665 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-43846HIGHGHSL-2025-016_Retrieval-based-Voice-Conversion-WebUIEPSS 0.9%CVE-2025-43847HIGHGHSL-2025-017_Retrieval-based-Voice-Conversion-WebUIEPSS 0.9%CVE-2024-1872HIGHButton <= 1.1.27 - Authenticated (Contributor+) PHP Object Injection in button_shortcodeEPSS 0.9%CVE-2025-26866HIGHApache HugeGraph-Server: RAFT and deserialization vulnerabilityEPSS 0.9%CVE-2024-0825HIGHVimeography: Vimeo Video Gallery WordPress Plugin <= 2.3.2 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.9%CVE-2024-2008HIGHModal Popup Box – Popup Builder, Show Offers And News in Popup <= 1.5.2 - Authenticated (Contributor+) PHP Object Injection in awl_modal_popup_box_shortcodeEPSS 0.9%CVE-2023-23930MEDIUMvantage6's Pickle serialization is insecureEPSS 0.9%CVE-2025-1913HIGHProduct Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data ParameterEPSS 0.9%CVE-2026-17086HIGHShortPixel Image Optimizer <= 6.5.5 - Authenticated (Author+) PHP Object Injection via Nested JSON Post ContentEPSS 0.9%CVE-2026-25747HIGHApache Camel LevelDB: Deserialization of Untrusted Data in Camel LevelDBEPSS 0.9%CVE-2026-40859HIGHApache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabledEPSS 0.9%CVE-2024-48112CRITICALA deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary coEPSS 0.9%CVE-2025-64439HIGHLangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializerEPSS 0.9%CVE-2023-2500HIGHGo Pricing - WordPress Responsive Pricing Tables <= 3.3.19 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.9%CVE-2025-43849HIGHGHSL-2025-019_Retrieval-based-Voice-Conversion-WebUIEPSS 0.9%CVE-2025-43850HIGHGHSL-2025-020_Retrieval-based-Voice-Conversion-WebUIEPSS 0.9%CVE-2019-2391MEDIUMJS-bson may incorrectly serialise some requestsEPSS 0.9%CVE-2026-40044CRITICALPachno 1.0.6 FileCache Deserialization Remote Code ExecutionEPSS 0.9%CVE-2025-32568CRITICALWordPress EmpikPlace for Woocommerce Plugin <= 1.4.3 - PHP Object Injection vulnerabilityEPSS 0.9%CVE-2025-32569CRITICALWordPress TableOn plugin <= 1.0.4.3 - PHP Object Injection vulnerabilityEPSS 0.9%