Fallos del tipo CWE-502

2665 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-16138HIGHRemote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO serviceEPSS 0.8%CVE-2023-46615MEDIUMWordPress KD Coming Soon Plugin <= 1.7 is vulnerable to PHP Object InjectionEPSS 0.8%CVE-2024-8003MEDIUMGo-Tribe gotribe-admin Log routes.go InitRoutes deserializationEPSS 0.8%CVE-2025-71364HIGHpicklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._startEPSS 0.8%CVE-2026-24892HIGHopenITCOCKPIT has Unsafe Deserialization in openITCOCKPIT Changelog HandlingEPSS 0.8%CVE-2021-32568HIGHDeserialization of Untrusted Data in zmister2016/mrdocEPSS 0.8%CVE-2024-1792HIGHCMB2 <= 2.10.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2023-24971HIGHIBM B2B Advanced Communication denial of serviceEPSS 0.8%CVE-2024-13770HIGHPuzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2026-48207CRITICALApache Fory: PyFory ReduceSerializer Incomplete Policy EnforcementEPSS 0.8%CVE-2026-41635CRITICALApache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCEEPSS 0.8%CVE-2024-1859HIGHSlider Responsive Slideshow – Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2021-42698HIGHAzeoTech DAQFactoryEPSS 0.8%CVE-2024-3740MEDIUMcym1102 nginxWebUI reload exec deserializationEPSS 0.8%CVE-2024-2025HIGHBuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.20 - Authenticated (Subscriber+) PHP Object Injection in get_simple_requestEPSS 0.8%CVE-2025-58748HIGHDataease H2 data source JDBC URL validation bypass leads to remote code executionEPSS 0.8%CVE-2024-1770HIGHMeta Tag Manager <= 3.0.2 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.8%CVE-2024-2693HIGHLink Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2024-13789CRITICALRavpage <= 2.31 - PHP Object InjectionEPSS 0.8%CVE-2026-39890CRITICALPraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition LoadingEPSS 0.8%