Weaknesses of type CWE-502

2,666 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2024-22369HIGHApache Camel: Camel-SQL: Unsafe Deserialization from JDBCAggregationRepositoryEPSS 0.7%CVE-2026-76404CRITICALRemote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server appEPSS 0.7%CVE-2026-0551HIGHPPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_rolesEPSS 0.7%CVE-2024-54136CRITICALUntrusted Deserialization in ClipBucket-v5 Version 5.5.1 Revision 199 and BelowEPSS 0.7%CVE-2022-42919HIGHPython 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python muEPSS 0.7%CVE-2023-49819HIGHWordPress Structured Content Plugin <= 1.5.3 is vulnerable to PHP Object InjectionEPSS 0.7%CVE-2025-48951CRITICALAuth0-PHP SDK Deserialization of Untrusted Data vulnerabilityEPSS 0.7%CVE-2026-44901HIGHWazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-10095HIGHProgress UI for WPF format provider unsafe deserialization vulnerabilityEPSS 0.7%CVE-2026-8135HIGHConcrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.EPSS 0.7%CVE-2025-34060CRITICALMonero Forum Remote Code Execution via Arbitrary File Read and Cookie ForgeryEPSS 0.7%CVE-2026-50076CRITICALApache Fory: Java ReplaceResolverSerializer deserialization checks bypassEPSS 0.7%CVE-2024-1353MEDIUMPHPEMS index.api.php index deserializationEPSS 0.7%CVE-2024-8016CRITICALThe Events Calendar Pro <= 7.0.2 - Authenticated (Administrator+) PHP Object Injection to Remote Code ExecutionEPSS 0.7%CVE-2025-42963CRITICALInsecure Deserialization in SAP NetWeaver Application Server for Java (Log Viewer )EPSS 0.7%CVE-2025-11938MEDIUMChurchCRM setup.php deserializationEPSS 0.7%CVE-2022-2440HIGHTheme Editor <= 2.8 - Authenticated (Admin+) PHAR DeserializationEPSS 0.7%CVE-2025-58756HIGHMONAI's unsafe torch usage may lead to arbitrary code executionEPSS 0.7%CVE-2025-65213CRITICALMooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_EPSS 0.7%CVE-2026-50589MEDIUMIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JEPSS 0.7%