Weaknesses of type CWE-502

2,668 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2025-49507CRITICALWordPress CozyStay theme < 1.7.1 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-49330CRITICALWordPress Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.3.0 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2026-31239CRITICALThe mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggiEPSS 0.6%CVE-2024-30227CRITICALWordPress Geo Controller plugin <= 8.6.4 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-7301CRITICALCVE-2026-7301EPSS 0.6%CVE-2026-21619LOWUnsafe Deserialization of Erlang Terms in hex_coreEPSS 0.6%CVE-2025-67729HIGHlmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()EPSS 0.6%CVE-2024-4838HIGHConvertPlus <= 3.5.26 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2026-24163HIGHNVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successEPSS 0.6%CVE-2026-14534HIGHFickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)EPSS 0.6%CVE-2026-16062MEDIUMEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ ContentEPSS 0.6%CVE-2025-60225CRITICALWordPress BugsPatrol theme <= 1.5.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-60214CRITICALWordPress Goldenblatt theme < 1.3.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-61880HIGHIn Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.EPSS 0.6%CVE-2025-32571HIGHWordPress TuriTop Booking System Plugin <= 1.0.10 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-10571MEDIUMIBM WebSphere Application Server Liberty is affected by a denial of serviceEPSS 0.6%CVE-2026-35300CRITICALVulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1EPSS 0.6%CVE-2025-32686HIGHWordPress Team Members plugin <= 3.4.4 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2026-27776HIGHIM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesignEPSS 0.6%CVE-2023-32513HIGHWordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object InjectionEPSS 0.6%