Weaknesses of type CWE-502

2,667 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-26885HIGHWordPress Assistant Plugin <= 1.5.1 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2026-41486HIGHRay: Remote Code Execution via Parquet Arrow Extension Type DeserializationEPSS 0.7%CVE-2026-8024CRITICALDeserialization vulnerability in ibaPDA and ibaDatCoordinatorEPSS 0.7%CVE-2025-7504HIGHFriends 3.5.1 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.7%CVE-2025-26999HIGHWordPress ProfileGrid Plugin <= 5.9.4.3 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2025-31612CRITICALWordPress CBX Poll plugin <= 2.0.4 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2024-37054HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploadEPSS 0.7%CVE-2026-22016HIGHVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). EPSS 0.7%CVE-2025-62373CRITICALPipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializerEPSS 0.7%CVE-2026-42472CRITICALUnsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from RediEPSS 0.7%CVE-2026-42473CRITICALUnsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the EPSS 0.7%CVE-2026-58163HIGHApache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the serverEPSS 0.7%CVE-2025-67617CRITICALWordPress Consult Aid theme <= 1.4.3 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2022-23535HIGHLiteDB contains Deserialization of Untrusted DataEPSS 0.7%CVE-2024-30228CRITICALWordPress Hercules Core plugin <= 6.4 - Auth. PHP Object Injection vulnerabilityEPSS 0.7%CVE-2024-12721HIGHCustom Product Tabs For WooCommerce <= 1.2.4 - Authenticated (Shop Manager+) PHP Object InjectionEPSS 0.7%CVE-2025-31932HIGHDeserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed oEPSS 0.7%CVE-2025-24357HIGHvLLM allows a malicious model RCE by torch.load in hf_model_weights_iteratorEPSS 0.7%CVE-2024-5871CRITICALWooCommerce - Social Login <= 2.6.2 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2024-4157HIGHContact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - PHP Object Injection via extractDynamicValuesEPSS 0.7%