Weaknesses of type CWE-502

2,666 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2024-12138MEDIUMhorilla create_skills deserializationEPSS 0.7%CVE-2023-46154MEDIUMWordPress e2pdf Plugin <= 1.20.18 is vulnerable to PHP Object InjectionEPSS 0.7%CVE-2017-20206CRITICALAppointments <= 2.2.1 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2017-20207CRITICALFlickr Gallery <= 1.5.2 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2023-7018CRITICALDeserialization of Untrusted Data in huggingface/transformersEPSS 0.7%CVE-2026-90777HIGHESPnet before 202609 Remote Code Execution via Unsafe DeserializationEPSS 0.7%CVE-2025-62703HIGHFugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServerEPSS 0.7%CVE-2025-23932CRITICALWordPress Quick Count Plugin <= 3.00 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2026-6023HIGHDeserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAXEPSS 0.7%CVE-2024-1198MEDIUMopenBI Phar User.php addxinzhi deserializationEPSS 0.7%CVE-2025-2622MEDIUMaizuda snail-job Workflow-Task Management Module check-node-expression getRuntime deserializationEPSS 0.7%CVE-2024-52413CRITICALWordPress Airin Blog theme <= 1.6.1 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2025-43960HIGHAdminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., usingEPSS 0.7%CVE-2025-29783CRITICALvLLM Allows Remote Code Execution via Mooncake IntegrationEPSS 0.7%CVE-2023-49772CRITICALWordPress Genesis Simple Love Plugin <= 2.0 is vulnerable to PHP Object InjectionEPSS 0.7%CVE-2023-49773CRITICALWordPress BCorp Shortcodes Plugin <= 0.23 is vulnerable to PHP Object InjectionEPSS 0.7%CVE-2026-14265HIGHRCE via Deserialization in AWS Advanced JDBC WrapperEPSS 0.7%CVE-2026-34877CRITICALAn issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or sEPSS 0.7%CVE-2026-24656LOWApache Karaf: Decanter log-socket collector has deserialization vulnerabilityEPSS 0.7%CVE-2026-93088CRITICALCVE-2026-93088EPSS 0.7%