Fallos del tipo CWE-502

2668 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-16723CRITICALRemote Code Execution in fastjson 1.2.68–1.2.83EPSS 0.7%CVE-2026-54752CRITICALNetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull RequestEPSS 0.7%CVE-2026-11363MEDIUMNinja Forms <= 3.14.6 - Authenticated (Administrator+) PHP Object Injection via Form ImportEPSS 0.7%CVE-2024-3954HIGHDitty – Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.7%CVE-2024-10913HIGHClone <= 2.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialized_replace'EPSS 0.7%CVE-2025-27816CRITICALA vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecurEPSS 0.7%CVE-2026-25615HIGHBlesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.EPSS 0.7%CVE-2024-7561HIGHThe Next <= 1.1.0 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.7%CVE-2025-33213HIGHNVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issueEPSS 0.7%CVE-2025-33214HIGHNVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserialization issue. A successfuEPSS 0.7%CVE-2026-57859HIGHe107 Second-Order Code Execution via eval()-Based Deserialization in e_array::unserialize()EPSS 0.7%CVE-2025-27300HIGHWordPress ADFO plugin <= 1.9.1 - Deserialization of untrusted data vulnerabilityEPSS 0.7%CVE-2025-27301HIGHWordPress NHR Options Table Manager Plugin <= 1.1.2 - Deserialization of untrusted data vulnerabilityEPSS 0.7%CVE-2026-26208HIGHADB Explorer Vulnerable to Remote Code Execution via Insecure DeserializationEPSS 0.7%CVE-2026-28220HIGHWazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master nodeEPSS 0.7%CVE-2025-27531CRITICALApache InLong: An arbitrary file read vulnerability for JDBCEPSS 0.7%CVE-2025-8227MEDIUMyanyutao0402 ChanCMS getArticle deserializationEPSS 0.7%CVE-2026-43866HIGHApache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolderEPSS 0.7%CVE-2024-10962HIGHMigration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2026-24157HIGHNVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploEPSS 0.7%