Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-32283HIGHWordPress Solar Energy theme <= 3.5 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2022-44558CRITICALThe AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilEPSS 0.6%CVE-2022-44562CRITICALThe system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may EPSS 0.6%CVE-2024-26289CRITICALRemote Code Inclusion Vulnerability in Multiple PMB VersionsEPSS 0.6%CVE-2022-44559CRITICALThe AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilEPSS 0.6%CVE-2024-28777HIGHIBM Cognos Controller code executionEPSS 0.6%CVE-2024-30222HIGHWordPress ARMember plugin <= 4.0.26 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-10771MEDIUMjeecgboot JimuReport DB2 JDBC testConnection deserializationEPSS 0.6%CVE-2024-6943MEDIUMZhongBangKeJi CRMEB CopyTaobaoServices.php downloadImage deserializationEPSS 0.6%CVE-2026-87930CRITICALMaxSite CMS through 109.6 PHP Object Injection via ci_sessionEPSS 0.6%CVE-2026-83803HIGHSentry: Unsafe pickle deserialization in Relocation FeatureEPSS 0.6%CVE-2023-35815LOWDevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.EPSS 0.6%CVE-2023-35814LOWDevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.EPSS 0.6%CVE-2026-15976CRITICALCVE-2026-15976EPSS 0.6%CVE-2025-26900CRITICALWordPress Flexmls® IDX Plugin Plugin <= 3.14.27 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-40555HIGHWordPress Flatsome Theme <= 3.17.5 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2024-13136MEDIUMwangl1989 mysiteforme ShiroConfig.java rememberMeManager deserializationEPSS 0.6%CVE-2026-28138HIGHWordPress uListing plugin <= 2.2.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2024-4471HIGH140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2026-35537LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may leadEPSS 0.6%