Fallos del tipo CWE-502

2668 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-45794HIGHOpenAM Unsafe Java Deserialization via SNSEPSS 0.6%CVE-2025-0724HIGHProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.6%CVE-2022-3568HIGHImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to PHAR DeserializationEPSS 0.6%CVE-2024-29136HIGHWordPress Tourfic plugin <= 2.11.17 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-24661HIGHWordPress Taxi Booking Manager for WooCommerce plugin <= 1.1.8 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2024-7486HIGHMultiPurpose <= 1.2.0 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2025-5497MEDIUMslackero phpwcms Feedimport processing.inc.php deserializationEPSS 0.6%CVE-2025-71321CRITICALpicklescan - Arbitrary File Writing via distutils Module BypassEPSS 0.6%CVE-2024-7434HIGHUltraPress <= 1.2.2 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-5724HIGHPhoto Video Gallery Master <= 1.5.3 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2026-12240HIGHExport User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name FieldEPSS 0.6%CVE-2024-6152HIGHFlipbox Builder <= 1.5 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-37055HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaEPSS 0.6%CVE-2024-11501HIGHGallery <= 1.3 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2025-14071HIGHLive Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output ShortcodeEPSS 0.6%CVE-2024-2694HIGHBetheme <= 27.5.6 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-10587HIGHFunnelforms Free <= 3.7.5.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2025-53606CRITICALApache Seata (incubating): Deserialization of untrusted Data in Apache Seata ServerEPSS 0.6%CVE-2024-30229HIGHWordPress Give plugin <= 3.4.2 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-43981CRITICALPresto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_foldeEPSS 0.6%