Weaknesses of type CWE-502

2,666 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-65883CRITICALJoomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0EPSS 0.8%CVE-2026-59940CRITICALSeroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationEPSS 0.8%CVE-2026-17061CRITICALDeserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026EPSS 0.8%CVE-2026-39890CRITICALPraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition LoadingEPSS 0.8%CVE-2026-7858CRITICALDeserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026xEPSS 0.8%CVE-2026-24747HIGHPyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint FilesEPSS 0.8%CVE-2025-2000CRITICALQiskit SDK code executionEPSS 0.8%CVE-2026-33337HIGHFirebird has a buffer overflow when parsing corrupted slice packetsEPSS 0.8%CVE-2025-69690CRITICALNetgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the EPSS 0.8%CVE-2022-2870MEDIUMlaravel deserializationEPSS 0.8%CVE-2026-5426CRITICALKnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey valueEPSS 0.8%CVE-2024-10079HIGHWP Easy Post Types <= 1.4.4 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.8%CVE-2025-45146CRITICALModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. ThiEPSS 0.8%CVE-2026-61484CRITICALApache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoSEPSS 0.8%CVE-2026-64608CRITICALApache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip pathsEPSS 0.8%CVE-2024-10932HIGHBackup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'EPSS 0.8%CVE-2022-3291MEDIUMSerialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.EPSS 0.8%CVE-2024-8922HIGHProduct Enquiry for WooCommerce <= 2.2.33.33 - Authenticated (Author+) PHP Object Injection in enquiry_detail.phpEPSS 0.8%CVE-2026-31219HIGHThe _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377fEPSS 0.8%CVE-2026-31218HIGHThe _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377fEPSS 0.8%