Fallos del tipo CWE-502

2674 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-24385HIGHWordPress Podlove Web Player plugin <= 5.9.1 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-39577HIGHWordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-39578HIGHWordPress Valiance theme <= 1.2 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-24216HIGHNVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of thisEPSS 0.3%CVE-2025-15246MEDIUMaizuda snail-job API FurySerializer.deserialize deserializationEPSS 0.3%CVE-2026-3048MEDIUMNexus Repository 3 - Improper LDAP Referral HandlingEPSS 0.3%CVE-2025-59050HIGHGreenshot — Insecure .NET deserialization via WM_COPYDATA enables local code executionEPSS 0.3%CVE-2025-46567MEDIUMLLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.pyEPSS 0.3%CVE-2025-63617MEDIUMktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fasEPSS 0.3%CVE-2025-53416HIGHFile Parsing Deserialization of Untrusted Data in DTN SoftEPSS 0.3%CVE-2023-28072HIGH Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious useEPSS 0.3%CVE-2025-8871MEDIUMEverest Forms (Pro) <= 1.9.7 - Unauthenticated PHP Object Injection via PHAR Deserialization in Form SignatureEPSS 0.3%CVE-2026-1235MEDIUMWP eCommerce <= 3.15.1 - Unauthenticated PHP Object InjectionEPSS 0.3%CVE-2025-23254HIGHNVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by locaEPSS 0.3%CVE-2025-67747HIGHFickling has missing detection for marshal.loads and types.FunctionType in unsafe modules listEPSS 0.3%CVE-2026-52777CRITICALYesWiki: Authenticated PHP Object Injection in BazarImportAction via unserializeEPSS 0.3%CVE-2026-39324CRITICALRack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserializationEPSS 0.3%CVE-2026-11857HIGHInsecure .NET Remoting deserialization in Quanos SCHEMA ST4 Client Update Service allows local privilege escalationEPSS 0.3%CVE-2024-0654MEDIUMDeepFaceLab Util.py deserializationEPSS 0.3%CVE-2026-100846HIGHMONAI before 1.5.2 Remote Code Execution via Pickle DeserializationEPSS 0.3%