Fallos del tipo CWE-502

2654 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2023-3343HIGHUser Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object InjectionEPSS 1.1%CVE-2023-36825CRITICALOrchid Deserialization of Untrusted Data vulnerability leads to Remote Code ExecutionEPSS 1.1%CVE-2024-10190CRITICALUnauthenticated Remote Code Execution in ElasticRendezvousHandler in horovod/horovodEPSS 1.1%CVE-2026-8365HIGHBlocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API FieldEPSS 1.1%CVE-2026-63767CRITICALktransformers Unauthenticated Pickle Deserialization RCE via ZMQEPSS 1.1%CVE-2023-3308MEDIUMwhaleal IceFrog Aviator Template Engine deserializationEPSS 1.1%CVE-2023-7334CRITICALChangjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCEEPSS 1.1%CVE-2023-30898CRITICALA vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versionsEPSS 1.1%CVE-2023-30899CRITICALA vulnerability has been identified in Siveillance Video 2020 R2 (All versions < V20.2 HotfixRev14), Siveillance Video 2020 R3 (All versionsEPSS 1.1%CVE-2025-7697CRITICALIntegration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val FunctionEPSS 1.1%CVE-2024-10936HIGHString Locator <= 2.6.6 - Unauthenticated PHP Object InjectionEPSS 1.1%CVE-2024-12312HIGHPrint Science Designer <= 1.3.152 - Unauthenticated PHP Object InjectionEPSS 1.1%CVE-2023-28667CRITICALThe Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels paraEPSS 1.1%CVE-2026-49121CRITICALAI Tensor Engine for ROCm (AITER) 0.1.14 Unauthenticated RCE via MessageQueue.recv() Pickle DeserializationEPSS 1.1%CVE-2021-33175—EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consumption due to the hanEPSS 1.1%CVE-2021-33176—VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memory consumption due toEPSS 1.1%CVE-2026-66808HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 1.1%CVE-2026-50515CRITICALAzure Service Bus Remote Code Execution VulnerabilityEPSS 1.1%CVE-2016-9585—Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passeEPSS 1.1%CVE-2024-11409HIGHGrid View Gallery <= 1.0 - Authenticated (Editor+) PHP Object InjectionEPSS 1.1%