Fallos del tipo CWE-502

2665 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-54469HIGHDell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged aEPSS 0.9%CVE-2026-57516HIGHRay < 2.56.0 Unsafe Deserialization RCE via WebDataset ReaderEPSS 0.9%CVE-2023-29006HIGHOrder GLPI plugin vulnerable to remote code execution from authenticated userEPSS 0.9%CVE-2024-0603HIGHZhiCms giftcontroller.php deserializationEPSS 0.9%CVE-2025-0465MEDIUMAquilaCMS categories deserializationEPSS 0.9%CVE-2026-86404HIGHArtemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by defaultEPSS 0.9%CVE-2023-6656MEDIUMDeepFaceLab DFLJPG.py deserializationEPSS 0.9%CVE-2025-56422CRITICALA deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.EPSS 0.9%CVE-2022-2561HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interactionEPSS 0.9%CVE-2024-4413CRITICALHotel Booking Lite <= 4.11.1 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2024-5335CRITICALUltimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2026-3452HIGHConcrete CMS below 9.4.8 is vulnerable to stored deserialization leading to RCE in the Express Entry List block.EPSS 0.9%CVE-2024-1731HIGHAuto Refresh Single Page <= 1.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.9%CVE-2024-1895HIGHEvent Monster <= 1.3.9 - Authenticated(Contributor+) PHP Object Injection via Custom MetaEPSS 0.9%CVE-2026-23946MEDIUMTendenci has Authenticated Remote Code Execution via Pickle DeserializationEPSS 0.9%CVE-2026-81657CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.8%CVE-2026-12118CRITICALIBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted dataEPSS 0.8%CVE-2026-16258CRITICALAjax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST EndpointEPSS 0.8%CVE-2026-70416CRITICALDell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with reEPSS 0.8%CVE-2023-38264MEDIUMIBM SDK, Java Technology Edition denial of serviceEPSS 0.8%