Weaknesses of type CWE-502

2,665 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-54469HIGHDell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged aEPSS 0.9%CVE-2026-57516HIGHRay < 2.56.0 Unsafe Deserialization RCE via WebDataset ReaderEPSS 0.9%CVE-2023-29006HIGHOrder GLPI plugin vulnerable to remote code execution from authenticated userEPSS 0.9%CVE-2024-0603HIGHZhiCms giftcontroller.php deserializationEPSS 0.9%CVE-2025-0465MEDIUMAquilaCMS categories deserializationEPSS 0.9%CVE-2026-86404HIGHArtemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by defaultEPSS 0.9%CVE-2023-6656MEDIUMDeepFaceLab DFLJPG.py deserializationEPSS 0.9%CVE-2025-56422CRITICALA deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.EPSS 0.9%CVE-2022-2561HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interactionEPSS 0.9%CVE-2024-4413CRITICALHotel Booking Lite <= 4.11.1 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2024-5335CRITICALUltimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2026-3452HIGHConcrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.EPSS 0.9%CVE-2024-1731HIGHAuto Refresh Single Page <= 1.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.9%CVE-2024-1895HIGHEvent Monster <= 1.3.9 - Authenticated(Contributor+) PHP Object Injection via Custom MetaEPSS 0.9%CVE-2026-23946MEDIUMTendenci has Authenticated Remote Code Execution via Pickle DeserializationEPSS 0.9%CVE-2026-81657CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.8%CVE-2026-12118CRITICALIBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted dataEPSS 0.8%CVE-2026-16258CRITICALAjax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST EndpointEPSS 0.8%CVE-2026-70416CRITICALDell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with reEPSS 0.8%CVE-2023-38264MEDIUMIBM SDK, Java Technology Edition denial of serviceEPSS 0.8%