Fallos del tipo CWE-502

2666 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2024-22369HIGHApache Camel: Camel-SQL: Unsafe Deserialization from JDBCAggregationRepositoryEPSS 0.7%CVE-2026-76404CRITICALRemote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server appEPSS 0.7%CVE-2026-0551HIGHPPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_rolesEPSS 0.7%CVE-2024-54136CRITICALUntrusted Deserialization in ClipBucket-v5 Version 5.5.1 Revision 199 and BelowEPSS 0.7%CVE-2022-42919HIGHPython 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python muEPSS 0.7%CVE-2023-49819HIGHWordPress Structured Content Plugin <= 1.5.3 is vulnerable to PHP Object InjectionEPSS 0.7%CVE-2025-48951CRITICALAuth0-PHP SDK Deserialization of Untrusted Data vulnerabilityEPSS 0.7%CVE-2026-44901HIGHWazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-10095HIGHProgress UI for WPF format provider unsafe deserialization vulnerabilityEPSS 0.7%CVE-2026-8135HIGHConcrete CMS 9.5.0 and below is vulnerable to RCE due to insecure deserialization occurring in the ExpressEntryList block controller.EPSS 0.7%CVE-2025-34060CRITICALMonero Forum Remote Code Execution via Arbitrary File Read and Cookie ForgeryEPSS 0.7%CVE-2026-50076CRITICALApache Fory: Java ReplaceResolverSerializer deserialization checks bypassEPSS 0.7%CVE-2024-1353MEDIUMPHPEMS index.api.php index deserializationEPSS 0.7%CVE-2024-8016CRITICALThe Events Calendar Pro <= 7.0.2 - Authenticated (Administrator+) PHP Object Injection to Remote Code ExecutionEPSS 0.7%CVE-2025-42963CRITICALInsecure Deserialization in SAP NetWeaver Application Server for Java (Log Viewer )EPSS 0.7%CVE-2025-11938MEDIUMChurchCRM setup.php deserializationEPSS 0.7%CVE-2022-2440HIGHTheme Editor <= 2.8 - Authenticated (Admin+) PHAR DeserializationEPSS 0.7%CVE-2025-58756HIGHMONAI's unsafe torch usage may lead to arbitrary code executionEPSS 0.7%CVE-2025-65213CRITICALMooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_EPSS 0.7%CVE-2026-50589MEDIUMIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JEPSS 0.7%