Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-16723CRITICALRemote Code Execution in fastjson 1.2.68–1.2.83EPSS 0.7%CVE-2026-54752CRITICALNetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull RequestEPSS 0.7%CVE-2026-11363MEDIUMNinja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form ImportEPSS 0.7%CVE-2024-3954HIGHDitty – Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.7%CVE-2024-10913HIGHClone <= 2.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialized_replace'EPSS 0.7%CVE-2025-27816CRITICALA vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecurEPSS 0.7%CVE-2026-25615HIGHBlesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.EPSS 0.7%CVE-2024-7561HIGHThe Next <= 1.1.0 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.7%CVE-2025-33213HIGHNVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issueEPSS 0.7%CVE-2025-33214HIGHNVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successfuEPSS 0.7%CVE-2026-57859HIGHe107 Second-Order Code Execution via eval()-Based Deserialization in e_array::unserialize()EPSS 0.7%CVE-2025-27300HIGHWordPress ADFO plugin <= 1.9.1 - Deserialization of untrusted data vulnerabilityEPSS 0.7%CVE-2025-27301HIGHWordPress NHR Options Table Manager Plugin <= 1.1.2 - Deserialization of untrusted data vulnerabilityEPSS 0.7%CVE-2026-26208HIGHADB Explorer Vulnerable to Remote Code Execution via Insecure DeserializationEPSS 0.7%CVE-2026-28220HIGHWazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master nodeEPSS 0.7%CVE-2025-27531CRITICALApache InLong: An arbitrary file read vulnerability for JDBCEPSS 0.7%CVE-2025-8227MEDIUMyanyutao0402 ChanCMS getArticle deserializationEPSS 0.7%CVE-2026-43866HIGHApache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolderEPSS 0.7%CVE-2024-10962HIGHMigration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2026-24157HIGHNVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploEPSS 0.7%