Fallos del tipo CWE-502

2669 resultados

Desserialização de dados não confiáveis

A aplicação reconstrói objetos a partir de dados recebidos (JSON, XML, binário) sem validar se o resultado é seguro. Um atacante pode injetar código malicioso ou estruturas que exploram o processo de desserialização para executar ações arbitrárias no servidor ou cliente.

Ejemplo

Um serviço Java desserializa um objeto enviado pelo usuário usando ObjectInputStream sem filtros. O atacante envia um payload serializado que, ao ser reconstituído, executa comandos do sistema. Cenário comum: aplicações legadas que confiam em dados de rede ou arquivos sem inspeção.

Cómo mitigar

Valide e filtre dados antes de desserializar — use listas de classes permitidas (whitelisting), implemente validação de schema, e prefira formatos simples (JSON com parse restritivo) em vez de binários com lógica automática. Para linguagens críticas como Java, use bibliotecas seguras ou desabilite gadgets perigosos.

CVE-2026-25925HIGHPowerDocu Affected by Remote Code Execution via Insecure DeserializationEPSS 0.5%CVE-2025-0841MEDIUMAridius XYZ News loadMore deserializationEPSS 0.5%CVE-2026-37579HIGHAn issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java compEPSS 0.5%CVE-2026-46386CRITICALOpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`EPSS 0.5%CVE-2025-5326MEDIUMzhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 verifyToken deserializationEPSS 0.5%CVE-2025-24601CRITICALWordPress FundPress plugin <= 2.0.6 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22606HIGHFickling has a bypass via runpy.run_path() and runpy.run_module()EPSS 0.5%CVE-2025-59007CRITICALWordPress TF Woo Product Grid Addon For Elementor Plugin <= 1.0.1 - Deserialization of untrusted data VulnerabilityEPSS 0.5%CVE-2024-53326HIGHLINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code eEPSS 0.5%CVE-2025-8963MEDIUMjeecgboot JimuReport Data Large Screen Template testConnection deserializationEPSS 0.5%CVE-2023-7032HIGH A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain EPSS 0.5%CVE-2025-4905MEDIUMiop-apl-uw basestation3 QC.py load_qc_pickl deserializationEPSS 0.5%CVE-2025-60245CRITICALWordPress WP User Manager plugin <= 2.9.12 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22333HIGHWordPress YITH WooCommerce Compare plugin <= 3.6.0 - Deserialization of untrusted data vulnerabilityEPSS 0.5%CVE-2026-22354HIGHWordPress Woocommerce Category Banner Management plugin <= 2.5.1 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-68526HIGHWordPress Modal Popup Box plugin <= 1.6.1 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-69294HIGHWordPress PeakShops theme <= 1.5.9 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-2043MEDIUMLinZhaoguan pb-cms Add New Topic admin#themes deserializationEPSS 0.5%CVE-2025-5552MEDIUMChestnutCMS API Endpoint exec deserializationEPSS 0.5%CVE-2026-90575MEDIUMPHPGurukul Small CRM Login Success login.php unserialize deserializationEPSS 0.5%