Weaknesses of type CWE-502

2,667 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-49839HIGHGHSL-2025-051: GPT-SoVITS Deserialization of Untrusted Data vulnerabilityEPSS 0.7%CVE-2026-45051CRITICALOpenAM Pre-auth RCE via Java Deserialization in WebAuthn Authenticator StorageEPSS 0.7%CVE-2025-4803HIGHGlossary by WPPedia <= 1.3.0 - Authenticated (Administrator+) PHP Object InjectionEPSS 0.7%CVE-2026-27749HIGHAvira Internet Security System Speedup Insecure DeserializationEPSS 0.7%CVE-2026-31223HIGHThe snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of thEPSS 0.7%CVE-2026-31222HIGHThe snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer clEPSS 0.7%CVE-2026-31224HIGHThe snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of thEPSS 0.7%CVE-2026-10035MEDIUMTurnkey bbPress by WeaverTheme <= 1.7.1 - Authenticated (Administrator+) PHP Object InjectionEPSS 0.7%CVE-2025-26967HIGHWordPress Events Calendar for GeoDirectory plugin <= 2.3.14 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2024-45852HIGHDeserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model toEPSS 0.7%CVE-2026-62997HIGHKedro-Datasets: Remote code execution in experimental `PyTorchDataset` via unsafe `torch.load`EPSS 0.7%CVE-2026-48775MEDIUMLangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loadingEPSS 0.7%CVE-2023-44392HIGHArbitrary code execution vulnerability when using shared Kubernetes clusterEPSS 0.7%CVE-2022-33947MEDIUMBIG-IP DNS TMUI Vulnerability CVE-2022-33947EPSS 0.7%CVE-2025-1186MEDIUMdayrui XunRuiCMS Api.php deserializationEPSS 0.7%CVE-2024-1748MEDIUMvan_der_Schaar LAB AutoPrognosis Release Note load_model_from_file deserializationEPSS 0.7%CVE-2024-0937MEDIUMvan_der_Schaar LAB synthcity PKL File load_from_file deserializationEPSS 0.7%CVE-2025-54923HIGHCWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity whEPSS 0.7%CVE-2025-23944HIGHWordPress WOOEXIM Plugin <= 5.0.0 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2023-34382MEDIUMWordPress Dokan Plugin <= 3.7.19 is vulnerable to PHP Object InjectionEPSS 0.7%