Weaknesses of type CWE-502

2,665 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-16138HIGHRemote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO serviceEPSS 0.8%CVE-2023-46615MEDIUMWordPress KD Coming Soon Plugin <= 1.7 is vulnerable to PHP Object InjectionEPSS 0.8%CVE-2024-8003MEDIUMGo-Tribe gotribe-admin Log routes.go InitRoutes deserializationEPSS 0.8%CVE-2025-71364HIGHpicklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._startEPSS 0.8%CVE-2026-24892HIGHopenITCOCKPIT has Unsafe Deserialization in openITCOCKPIT Changelog HandlingEPSS 0.8%CVE-2021-32568HIGHDeserialization of Untrusted Data in zmister2016/mrdocEPSS 0.8%CVE-2024-1792HIGHCMB2 <= 2.10.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2023-24971HIGHIBM B2B Advanced Communication denial of serviceEPSS 0.8%CVE-2024-13770HIGHPuzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2026-48207CRITICALApache Fory: PyFory ReduceSerializer Incomplete Policy EnforcementEPSS 0.8%CVE-2026-41635CRITICALApache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCEEPSS 0.8%CVE-2024-1859HIGHSlider Responsive Slideshow – Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2021-42698HIGHAzeoTech DAQFactoryEPSS 0.8%CVE-2024-3740MEDIUMcym1102 nginxWebUI reload exec deserializationEPSS 0.8%CVE-2024-2025HIGHBuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.20 - Authenticated (Subscriber+) PHP Object Injection in get_simple_requestEPSS 0.8%CVE-2025-58748HIGHDataease H2 data source JDBC URL validation bypass leads to remote code executionEPSS 0.8%CVE-2024-1770HIGHMeta Tag Manager <= 3.0.2 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.8%CVE-2024-2693HIGHLink Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2024-13789CRITICALRavpage <= 2.31 - PHP Object InjectionEPSS 0.8%CVE-2026-39890CRITICALPraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition LoadingEPSS 0.8%