Weaknesses of type CWE-502

2,667 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2024-54367CRITICALWordPress ForumWP plugin <= 2.1.0 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2020-7811MEDIUMSamsung Update Local Privilege Escalation VulnerabilityEPSS 0.7%CVE-2025-48200CRITICALThe sr_feuser_register extension through 12.4.8 for TYPO3 allows Remote Code Execution.EPSS 0.7%CVE-2024-0959MEDIUMStanfordVL GibsonEnv pposgd_fuse.py cloudpickle.load deserializationEPSS 0.7%CVE-2026-3245HIGHA deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.EPSS 0.7%CVE-2026-25524HIGHOpenMage LTS's Phar Deserialization leads to Remote Code ExecutionEPSS 0.7%CVE-2026-83557MEDIUMjackson-databind omits java.lang.Comparable from DefaultBaseTypeLimitingValidator's unsafe base typesEPSS 0.7%CVE-2024-13906HIGHGallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object InjectionEPSS 0.7%CVE-2021-32828MEDIUMRegular expression Denial of Service in MooToolsEPSS 0.7%CVE-2026-93872HIGHCotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb ParameterEPSS 0.7%CVE-2024-13921HIGHOrder Export & Order Import for WooCommerce <= 2.6.0 - Authenticated (Admin+) PHP Object Injection via form_data ParameterEPSS 0.7%CVE-2026-78614HIGHDimension SQL Injection in Audit ReportEPSS 0.7%CVE-2026-78612HIGHDimension SQL Injection in Scheduled ReportEPSS 0.7%CVE-2024-7435HIGHAttire <= 2.0.6 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.7%CVE-2025-34394CRITICALBarracuda RMM < 2025.1.1 Service Center .NET Remoting Deserialization RCEEPSS 0.7%CVE-2017-20208CRITICALRegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object InjectionEPSS 0.7%CVE-2024-54273CRITICALWordPress Mail Picker plugin <= 1.0.14 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2023-25770CRITICALController stack overflow on decoding messages from the serverEPSS 0.7%CVE-2025-31084CRITICALWordPress Sunshine Photo Cart plugin <= 3.4.10 - PHP Object Injection VulnerabilityEPSS 0.7%CVE-2026-57822MEDIUMApache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of serviceEPSS 0.7%