Fallos del tipo CWE-502

2648 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2025-20124CRITICALCisco Identity Services Engine Java Deserialization VulnerabilityEPSS 18.5%CVE-2022-38142CRITICAL Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway EPSS 18.2%CVE-2023-1669HIGHSEOPress < 6.5.0.3 - Admin+ PHP Object InjectionEPSS 17.7%CVE-2024-10456CRITICALDelta Electronics InfraSuite Device Master Deserialization of Untrusted DataEPSS 17.6%CVE-2021-24040—Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicioEPSS 17.4%CVE-2022-28685HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802EPSS 17.2%CVE-2023-26359CRITICALAdobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionEPSS 17.0%KEVCVE-2021-43297—Dubbo Hessian cause RCE when parse errorEPSS 17.0%CVE-2022-36964HIGHSolarWinds Platform Deserialization of Untrusted DataEPSS 16.8%CVE-2022-1660CRITICALKeysight N6854A Geolocation server and N6841A RF Sensor softwareEPSS 16.8%CVE-2023-47207CRITICALDelta Electronics InfraSuite Device Master Deserialization of Untrusted DataEPSS 16.6%CVE-2021-39141HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 16.1%CVE-2023-1347HIGHCustomizer Export/Import < 0.9.6 - Admin+ PHP Object InjectionEPSS 16.0%CVE-2026-16723CRITICALRemote Code Execution in fastjson 1.2.68–1.2.83EPSS 16.0%CVE-2017-0903—RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem speEPSS 15.9%CVE-2026-25874CRITICALLeRobot Unsafe Deserialization Remote Code Execution via gRPCEPSS 15.5%CVE-2021-21350MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 15.2%CVE-2022-36971CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authEPSS 15.0%CVE-2024-4044HIGHDeserialization of Untrusted Data Vulnerability in FlexLogger and InstrumentStudioEPSS 14.7%CVE-2024-8069MEDIUMLimited remote code execution with privilege of a NetworkService Account accessEPSS 14.6%KEV