Fallos del tipo CWE-502

2693 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2024-3467HIGHDeserialization of Untrusted Data in AVEVA PI Asset Framework ClientEPSS 0.2%CVE-2026-100843HIGHMONAI before 1.6.0 Remote Code Execution via algo_from_pickleEPSS 0.2%CVE-2026-0859MEDIUMTYPO3 CMS Allows Insecure Deserialization via Mailer File SpoolEPSS 0.2%CVE-2025-11739HIGHCWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges wheEPSS 0.2%CVE-2025-40759HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP EPSS 0.2%CVE-2025-46738MEDIUMDeserialization of Untrusted DataEPSS 0.2%CVE-2025-31935MEDIUMSubnet Solutions PowerSYSTEM Center Deserialization of Untrusted DataEPSS 0.2%CVE-2025-30025MEDIUMThe communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalatioEPSS 0.2%CVE-2025-2180MEDIUMCheckov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code ExecutionEPSS 0.2%CVE-2022-1984MEDIUMThis issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versiEPSS 0.2%CVE-2023-32737HIGHA vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do not properly restriEPSS 0.2%CVE-2025-48535HIGHIn assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a lauEPSS 0.2%CVE-2026-24237HIGHNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of EPSS 0.2%CVE-2026-24221HIGHNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of EPSS 0.2%CVE-2024-54678HIGHA vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All vEPSS 0.2%CVE-2025-4393MEDIUMMedtronic MyCareLink Patient Monitor Deserialization VulnerabilityEPSS 0.2%CVE-2025-41701HIGHBeckhoff: Deserialization of untrusted data by TwinCAT 3 EngineeringEPSS 0.2%CVE-2025-61677LOWDataChain: Deserialization of Untrusted Data from Environment VariablesEPSS 0.2%CVE-2026-24228HIGHNVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploitEPSS 0.2%CVE-2025-48018HIGHDeserialization of Untrusted DataEPSS 0.2%