Fallos del tipo CWE-502

2674 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2025-47579CRITICALWordPress Photography Theme <= 7.7.2 - PHP Object Injection VulnerabilityEPSS 0.3%CVE-2025-53584HIGHWordPress WP Ticket Customer Service Software & Support Ticket System Plugin <= 6.0.2 - PHP Object Injection VulnerabilityEPSS 0.3%CVE-2026-10748HIGHNexus Repository 3 - Remote Code Execution via License DeserializationEPSS 0.3%CVE-2025-3162MEDIUMInternLM LMDeploy PT File utils.py load_weight_ckpt deserializationEPSS 0.3%CVE-2025-65035MEDIUMGLPI Database Inventory Plugin Vulnerable to Stored Object InjectionEPSS 0.3%CVE-2024-32876HIGHNewPipe has potential security vulnerability when importing settingsEPSS 0.3%CVE-2026-14723MEDIUMAD-Security AD_Miner Cache analyse_cache.py request_a deserializationEPSS 0.3%CVE-2026-77092HIGHContent Extractor Privilege EscalationEPSS 0.3%CVE-2026-15531MEDIUMyashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserializationEPSS 0.3%CVE-2025-15117LOWDromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserializationEPSS 0.3%CVE-2025-33247HIGHNVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful expEPSS 0.3%CVE-2025-5174MEDIUMerdogant pypickle pypickle.py load deserializationEPSS 0.3%CVE-2026-83603HIGHNetdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCEEPSS 0.3%CVE-2026-15555HIGHJboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshallerEPSS 0.3%CVE-2026-56095HIGHInsecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)EPSS 0.3%CVE-2026-60412HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version EPSS 0.3%CVE-2026-60392HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supporteEPSS 0.3%CVE-2026-22248HIGHGLPI affected by Remote Code Execution via malicious uploadEPSS 0.3%CVE-2026-22384CRITICALWordPress Applay - Shortcodes plugin <= 3.7 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-1286HIGHCWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote cEPSS 0.3%