Fallos del tipo CWE-502

2666 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-32590HIGHMirror-registry: remote code execution using pickle deserializationEPSS 0.8%CVE-2023-1399HIGH N6854A Geolocation Server versions 2.4.2 are vulnerable to untrusted data deserialization, which may allow a malicious actor to escalate prEPSS 0.8%CVE-2026-4851CRITICALGRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserializationEPSS 0.8%CVE-2026-48853CRITICALRemote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpcEPSS 0.8%CVE-2026-34084CRITICALPhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::loadEPSS 0.8%CVE-2026-64606CRITICALApache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interfaceEPSS 0.8%CVE-2025-11622HIGHInsecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privilegEPSS 0.8%CVE-2026-73699HIGHFileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()EPSS 0.8%CVE-2024-1750MEDIUMTemmokuMVC Image Download images_get_down.php img_replace deserializationEPSS 0.8%CVE-2024-5085HIGHHash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2025-59285HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-31317HIGHIn multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to uEPSS 0.8%CVE-2026-33725HIGHMetabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization ImportEPSS 0.8%CVE-2026-81757HIGHWordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerabilityEPSS 0.8%CVE-2024-13889HIGHWordPress Importer <= 0.8.3 - Authenticated (Administrator+) PHP Object InjectionEPSS 0.8%CVE-2025-5499MEDIUMslackero phpwcms image_resized.php getimagesize deserializationEPSS 0.8%CVE-2025-30012CRITICALMultiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)EPSS 0.8%CVE-2024-37060HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously craftEPSS 0.8%CVE-2026-7566MEDIUMLearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File UploadEPSS 0.8%CVE-2024-13410CRITICALCozyStay <= 1.7.0 and TinySalt <= 3.9.0 - Unauthenticated PHP Object Injection in ajax_handlerEPSS 0.8%