Fallos del tipo CWE-502

2668 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2025-32283HIGHWordPress Solar Energy theme <= 3.5 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2022-44558CRITICALThe AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilEPSS 0.6%CVE-2022-44562CRITICALThe system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may EPSS 0.6%CVE-2024-26289CRITICALRemote Code Inclusion Vulnerability in Multiple PMB VersionsEPSS 0.6%CVE-2022-44559CRITICALThe AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilEPSS 0.6%CVE-2024-28777HIGHIBM Cognos Controller code executionEPSS 0.6%CVE-2024-30222HIGHWordPress ARMember plugin <= 4.0.26 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-10771MEDIUMjeecgboot JimuReport DB2 JDBC testConnection deserializationEPSS 0.6%CVE-2024-6943MEDIUMZhongBangKeJi CRMEB CopyTaobaoServices.php downloadImage deserializationEPSS 0.6%CVE-2026-87930CRITICALMaxSite CMS through 109.6 PHP Object Injection via ci_sessionEPSS 0.6%CVE-2026-83803HIGHSentry: Unsafe pickle deserialization in Relocation FeatureEPSS 0.6%CVE-2023-35815LOWDevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.EPSS 0.6%CVE-2023-35814LOWDevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.EPSS 0.6%CVE-2026-15976CRITICALCVE-2026-15976EPSS 0.6%CVE-2025-26900CRITICALWordPress Flexmls® IDX Plugin Plugin <= 3.14.27 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-40555HIGHWordPress Flatsome Theme <= 3.17.5 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2024-13136MEDIUMwangl1989 mysiteforme ShiroConfig.java rememberMeManager deserializationEPSS 0.6%CVE-2026-28138HIGHWordPress uListing plugin <= 2.2.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2024-4471HIGH140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2026-35537LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may leadEPSS 0.6%