Fallos del tipo CWE-502

2674 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-63630LOWBentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfiltration via RFC 3161 RequestsEPSS 0.3%CVE-2026-23971HIGHWordPress WoodMart theme <= 8.3.8 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-8612MEDIUMWWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code executionEPSS 0.3%CVE-2024-38759MEDIUMWordPress Search & Replace plugin <= 3.2.2 - Deserialization of untrusted data vulnerabilityEPSS 0.3%CVE-2024-12703HIGHCWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote cEPSS 0.3%CVE-2026-40993HIGHUnfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database EntryEPSS 0.3%CVE-2026-91827HIGHNinja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV ExportEPSS 0.3%CVE-2026-96745MEDIUMPHP object injection via unsuppressible __pclass class inference in command monitoring eventsEPSS 0.3%CVE-2026-25204MEDIUMDeserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process aEPSS 0.3%CVE-2024-34075MEDIUMkurwov vulnerable to Denial of Service due to improper data sanitizationEPSS 0.3%CVE-2025-69276LOWSpectrum insecure deserialiationEPSS 0.3%CVE-2024-39630MEDIUMWordPress Timetable and Event Schedule by MotoPress plugin <= 2.4.13 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2025-60038HIGHA vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by paEPSS 0.3%CVE-2025-60037HIGHA vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by paEPSS 0.3%CVE-2023-26592LOWDeserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated userEPSS 0.3%CVE-2025-11157HIGHArbitrary Code Execution in feast-dev/feastEPSS 0.3%CVE-2025-70559MEDIUMpdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python picklEPSS 0.3%CVE-2024-4200HIGHProgress Telerik Reporting Local Deserialization VulnerabilityEPSS 0.3%CVE-2025-26397HIGHSolarWinds Observability Self-Hosted Deserialization of Untrusted Data Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-52357MEDIUMVulnerability of serialization/deserialization mismatch in the vibration framework.Successful exploitation of this vulnerability may affect EPSS 0.3%