Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-30892HIGHWordPress WpTravelly Plugin <= 1.8.7 - PHP Object Injection vulnerabilityEPSS 0.7%CVE-2025-8227MEDIUMyanyutao0402 ChanCMS getArticle deserializationEPSS 0.7%CVE-2025-34153CRITICALHyland OnBase < 17.0.2.87 .NET Remoting TCP Channel Unauthenticated RCEEPSS 0.7%CVE-2025-0428HIGHAI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_export_promptsEPSS 0.7%CVE-2025-0429HIGHAI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_export_ai_formsEPSS 0.7%CVE-2026-3357HIGHIBM Langflow Desktop FAISS Vector Store Remote Code Execution via malicious Pickle fileEPSS 0.7%CVE-2026-96560CRITICALLightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control ChannelEPSS 0.7%CVE-2026-76395HIGHRemote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI ToolkitEPSS 0.7%CVE-2020-37071CRITICALCraftCMS 3 vCard Plugin 1.0.0 - Remote Code ExecutionEPSS 0.7%CVE-2026-13293HIGHIBM MQ Java messaging is vulnerable to remote code executionEPSS 0.7%CVE-2026-9291HIGHInsecure Deserialization in Amazon Braket SDK Job Results ProcessingEPSS 0.6%CVE-2026-65617HIGHPotential remote code execution on an Artifactory package service container.EPSS 0.6%CVE-2024-1432MEDIUMDeepFaceLab main.py apply_xseg deserializationEPSS 0.6%CVE-2025-15672HIGHChama < 1.0.13 - Unauthenticated PHP Object InjectionEPSS 0.6%CVE-2024-24797CRITICALWordPress ERE Recently Viewed Plugin <= 1.3 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2026-41731HIGHIn Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserializationEPSS 0.6%CVE-2023-52181CRITICALWordPress Theme per user Plugin <= 1.0.1 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2024-48033CRITICALWordPress Talkback plugin <= 1.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-2566CRITICALDeserialization of Untrusted Data in Kaleris Navis N4EPSS 0.6%CVE-2025-58757HIGHMONAI's unsafe use of Pickle deserialization may lead to RCEEPSS 0.6%