Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-45794HIGHOpenAM Unsafe Java Deserialization via SNSEPSS 0.6%CVE-2025-0724HIGHProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.6%CVE-2022-3568HIGHImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to PHAR DeserializationEPSS 0.6%CVE-2024-29136HIGHWordPress Tourfic plugin <= 2.11.17 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-24661HIGHWordPress Taxi Booking Manager for WooCommerce plugin <= 1.1.8 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2024-7486HIGHMultiPurpose <= 1.2.0 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2025-5497MEDIUMslackero phpwcms Feedimport processing.inc.php deserializationEPSS 0.6%CVE-2025-71321CRITICALpicklescan - Arbitrary File Writing via distutils Module BypassEPSS 0.6%CVE-2024-7434HIGHUltraPress <= 1.2.2 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-5724HIGHPhoto Video Gallery Master <= 1.5.3 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2026-12240HIGHExport User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name FieldEPSS 0.6%CVE-2024-6152HIGHFlipbox Builder <= 1.5 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-37055HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaEPSS 0.6%CVE-2024-11501HIGHGallery <= 1.3 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2025-14071HIGHLive Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output ShortcodeEPSS 0.6%CVE-2024-2694HIGHBetheme <= 27.5.6 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-10587HIGHFunnelforms Free <= 3.7.5.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2025-53606CRITICALApache Seata (incubating): Deserialization of untrusted Data in Apache Seata ServerEPSS 0.6%CVE-2024-30229HIGHWordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-43981CRITICALPresto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_foldeEPSS 0.6%