Fallos del tipo CWE-502

2673 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-35502MEDIUMDeserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow anEPSS 0.4%CVE-2022-27579—A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all versions up to and incEPSS 0.4%CVE-2026-47878MEDIUMUnsafe Java deserialization in DefaultExecutionContextSerializer without class allowlistEPSS 0.4%CVE-2026-24239HIGHNVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution.EPSS 0.4%CVE-2026-24267HIGHNVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attaEPSS 0.4%CVE-2025-31047HIGHWordPress Themify Edmin theme <= 2.0.0 - PHP Object Injection VulnerabilityEPSS 0.4%CVE-2026-7818HIGHpgAdmin 4: Unsafe deserialization (CWE-502) in file-backed session manager leads to remote code executionEPSS 0.4%CVE-2025-50198HIGHChamilo: Deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parametersEPSS 0.4%CVE-2025-54719HIGHWordPress Yogi - Health Beauty & Yoga Theme <= 2.9.2 - Deserialization of untrusted data VulnerabilityEPSS 0.3%CVE-2026-48517MEDIUMMessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic argumentsEPSS 0.3%CVE-2026-47472HIGHNVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could caEPSS 0.3%CVE-2026-24815CRITICALA XStream Security Vulnerability in XML Deserialization in datavane/tisEPSS 0.3%CVE-2024-13288MEDIUMMonster Menus - Critical - Arbitrary PHP code execution - SA-CONTRIB-2024-052EPSS 0.3%CVE-2025-46183HIGHThe Utils.deserialize function in pgCodeKeeper 10.12.0 processes serialized data from untrusted sources. If an attacker provides a speciallyEPSS 0.3%CVE-2025-13913MEDIUMInductive Automation Ignition Software Deserialization of Untrusted DataEPSS 0.3%CVE-2026-87083MEDIUMtile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserializationEPSS 0.3%CVE-2026-11815MEDIUMInsecure Deserialization via MITM in Layer 7 Policy ManagerEPSS 0.3%CVE-2026-45134HIGHLangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warningEPSS 0.3%CVE-2026-25359HIGHWordPress Pendulum theme < 3.1.5 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-25358HIGHWordPress Meloo theme < 2.8.2 - PHP Object Injection vulnerabilityEPSS 0.3%