Weaknesses of type CWE-502

2,666 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-32590HIGHMirror-registry: remote code execution using pickle deserializationEPSS 0.8%CVE-2023-1399HIGH N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate prEPSS 0.8%CVE-2026-4851CRITICALGRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserializationEPSS 0.8%CVE-2026-48853CRITICALRemote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpcEPSS 0.8%CVE-2026-34084CRITICALPhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::loadEPSS 0.8%CVE-2026-64606CRITICALApache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interfaceEPSS 0.8%CVE-2025-11622HIGHInsecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privilegEPSS 0.8%CVE-2026-73699HIGHFileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()EPSS 0.8%CVE-2024-1750MEDIUMTemmokuMVC Image Download images_get_down.php img_replace deserializationEPSS 0.8%CVE-2024-5085HIGHHash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2025-59285HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-31317HIGHIn multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to uEPSS 0.8%CVE-2026-33725HIGHMetabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization ImportEPSS 0.8%CVE-2026-81757HIGHWordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerabilityEPSS 0.8%CVE-2024-13889HIGHWordPress Importer <= 0.8.3 - Authenticated (Administrator+) PHP Object InjectionEPSS 0.8%CVE-2025-5499MEDIUMslackero phpwcms image_resized.php getimagesize deserializationEPSS 0.8%CVE-2025-30012CRITICALMultiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)EPSS 0.8%CVE-2024-37060HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously craftEPSS 0.8%CVE-2026-7566MEDIUMLearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File UploadEPSS 0.8%CVE-2024-13410CRITICALCozyStay <= 1.7.0 and TinySalt <= 3.9.0 - Unauthenticated PHP Object Injection in ajax_handlerEPSS 0.8%