Weaknesses of type CWE-502

2,667 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2022-2886MEDIUMLaravel deserializationEPSS 0.7%CVE-2021-47952CRITICALpython jsonpickle 2.0.0 Remote Code Execution via py/reprEPSS 0.7%CVE-2022-35872HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b202EPSS 0.7%CVE-2025-5662CRITICALDeserialization Vulnerability in h2oai/h2o-3EPSS 0.7%CVE-2026-7871CRITICALInsecure Deserialization in Redis Cache BackendEPSS 0.7%CVE-2026-20340HIGHCisco Secure Firewall Management Center Software Deserialization Arbitrary Root Command Execution VulnerabilityEPSS 0.7%CVE-2026-3017HIGHSmart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object InjectionEPSS 0.7%CVE-2025-50004HIGHWordPress JupiterX Core plugin <= 4.10.1 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2025-1556MEDIUMwestboy CicadasCMS Template Management system deserializationEPSS 0.7%CVE-2025-66455CRITICALLMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.pyEPSS 0.7%CVE-2025-7876MEDIUMMetasoft 美特软件 MetaCRM download.jsp AnalyzeParam deserializationEPSS 0.7%CVE-2026-47623HIGHNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of thEPSS 0.7%CVE-2024-24550HIGHBludit - Remote Code Execution (RCE) through File APIEPSS 0.7%CVE-2026-29782HIGHOpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2EPSS 0.7%CVE-2025-31087CRITICALWordPress Multiple Shipping And Billing Address For Woocommerce plugin <= 1.5 - PHP Object Injection VulnerabilityEPSS 0.7%CVE-2022-2439HIGHEasy Digital Downloads – Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR DeserializationEPSS 0.7%CVE-2023-49777CRITICALWordPress YITH WooCommerce Product Add-Ons Plugin <= 4.3.0 is vulnerable to PHP Object InjectionEPSS 0.7%CVE-2026-31235CRITICALThe imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py moEPSS 0.7%CVE-2025-49838HIGHGHSL-2025-050: GPT-SoVITS Deserialization of Untrusted Data vulnerabilityEPSS 0.7%CVE-2025-49837HIGHGHSL-2025-049: GPT-SoVITS Deserialization of Untrusted Data vulnerabilityEPSS 0.7%