Falhas do tipo CWE-502

2.648 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2025-20124CRITICALCisco Identity Services Engine Java Deserialization VulnerabilityEPSS 18.5%CVE-2022-38142CRITICAL Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through the Device-Gateway EPSS 18.2%CVE-2023-1669HIGHSEOPress < 6.5.0.3 - Admin+ PHP Object InjectionEPSS 17.7%CVE-2024-10456CRITICALDelta Electronics InfraSuite Device Master Deserialization of Untrusted DataEPSS 17.6%CVE-2021-24040Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicioEPSS 17.4%CVE-2022-28685HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802EPSS 17.2%CVE-2023-26359CRITICALAdobe ColdFusion Deserialization of Untrusted Data Arbitrary code executionEPSS 17.0%KEVCVE-2021-43297Dubbo Hessian cause RCE when parse errorEPSS 17.0%CVE-2022-36964HIGHSolarWinds Platform Deserialization of Untrusted DataEPSS 16.8%CVE-2022-1660CRITICALKeysight N6854A Geolocation server and N6841A RF Sensor softwareEPSS 16.8%CVE-2023-47207CRITICALDelta Electronics InfraSuite Device Master Deserialization of Untrusted DataEPSS 16.6%CVE-2021-39141HIGHXStream is vulnerable to an Arbitrary Code Execution attackEPSS 16.1%CVE-2023-1347HIGHCustomizer Export/Import < 0.9.6 - Admin+ PHP Object InjectionEPSS 16.0%CVE-2026-16723CRITICALRemote Code Execution in fastjson 1.2.68–1.2.83EPSS 16.0%CVE-2017-0903RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem speEPSS 15.9%CVE-2026-25874CRITICALLeRobot Unsafe Deserialization Remote Code Execution via gRPCEPSS 15.5%CVE-2021-21350MEDIUMXStream is vulnerable to an Arbitrary Code Execution attackEPSS 15.2%CVE-2022-36971CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authEPSS 15.0%CVE-2024-4044HIGHDeserialization of Untrusted Data Vulnerability in FlexLogger and InstrumentStudioEPSS 14.7%CVE-2024-8069MEDIUMLimited remote code execution with privilege of a NetworkService Account accessEPSS 14.6%KEV