Weaknesses of type CWE-502

2,666 results

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados serializados (JSON, XML, binário) recebidos de fontes externas sem validar adequadamente se o conteúdo é legítimo. Um atacante pode injetar código malicioso ou objetos especialmente crafted que são executados durante a desserialização, comprometendo toda a aplicação.

Example

Um servidor Java desserializa objetos recebidos em requisições HTTP usando ObjectInputStream, sem verificar a classe ou origem dos dados. Um atacante envia um objeto serializado contendo uma cadeia de gadgets (RCE via biblioteca como Apache Commons Collections) que é executada assim que o objeto é reconstruído em memória.

How to mitigate

Valide e liste explicitamente as classes que podem ser desserializadas (whitelist). Para JSON/XML, use parsers que não executem código (como JSON simples, evite eval). Considere alternativas seguras como Protocol Buffers ou MessagePack, e mantenha bibliotecas críticas atualizadas.

CVE-2026-46386CRITICALOpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`EPSS 0.5%CVE-2026-22606HIGHFickling has a bypass via runpy.run_path() and runpy.run_module()EPSS 0.5%CVE-2025-59007CRITICALWordPress TF Woo Product Grid Addon For Elementor Plugin <= 1.0.1 - Deserialization of untrusted data VulnerabilityEPSS 0.5%CVE-2025-5326MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 verifyToken deserializationEPSS 0.5%CVE-2025-24601CRITICALWordPress FundPress plugin <= 2.0.6 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2024-53326HIGHLINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code eEPSS 0.5%CVE-2025-4905MEDIUMiop-apl-uw basestation3 QC.py load_qc_pickl deserializationEPSS 0.5%CVE-2025-8963MEDIUMjeecgboot JimuReport Data Large Screen Template testConnection deserializationEPSS 0.5%CVE-2023-7032HIGH A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain EPSS 0.5%CVE-2025-60245CRITICALWordPress WP User Manager plugin <= 2.9.12 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-69294HIGHWordPress PeakShops theme <= 1.5.9 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22333HIGHWordPress YITH WooCommerce Compare plugin <= 3.6.0 - Deserialization of untrusted data vulnerabilityEPSS 0.5%CVE-2025-68526HIGHWordPress Modal Popup Box plugin <= 1.6.1 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-2043MEDIUMLinZhaoguan pb-cms Add New Topic admin#themes deserializationEPSS 0.5%CVE-2026-22354HIGHWordPress Woocommerce Category Banner Management plugin <= 2.5.1 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-5552MEDIUMChestnutCMS API Endpoint exec deserializationEPSS 0.5%CVE-2026-90575MEDIUMPHPGurukul Small CRM Login Success login.php unserialize deserializationEPSS 0.5%CVE-2025-3250MEDIUMelunez eladmin Maintenance Management Module testConnect deserializationEPSS 0.5%CVE-2025-2376MEDIUMviames Pair Framework PHP Object UserRemember.php getCookieContent deserializationEPSS 0.5%CVE-2025-61765MEDIUMpython-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deploymentsEPSS 0.5%