Falhas do tipo CWE-502

2.668 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2025-65035MEDIUMGLPI Database Inventory Plugin Vulnerable to Stored Object InjectionEPSS 0.3%CVE-2025-3162MEDIUMInternLM LMDeploy PT File utils.py load_weight_ckpt deserializationEPSS 0.3%CVE-2024-32876HIGHNewPipe has potential security vulnerability when importing settingsEPSS 0.3%CVE-2026-10748HIGHNexus Repository 3 - Remote Code Execution via License DeserializationEPSS 0.3%CVE-2026-77092HIGHContent Extractor Privilege EscalationEPSS 0.3%CVE-2026-15531MEDIUMyashbhalgat HashNeRF-pytorch Checkpoint File run_nerf.py torch.load deserializationEPSS 0.3%CVE-2025-15117LOWDromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserializationEPSS 0.3%CVE-2026-14723MEDIUMAD-Security AD_Miner Cache analyse_cache.py request_a deserializationEPSS 0.3%CVE-2025-33247HIGHNVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful expEPSS 0.3%CVE-2026-83603HIGHNetdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCEEPSS 0.3%CVE-2026-60412HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version EPSS 0.3%CVE-2026-15555HIGHJboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshallerEPSS 0.3%CVE-2026-56095HIGHInsecure Deserialization in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)EPSS 0.3%CVE-2026-60392HIGHVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supporteEPSS 0.3%CVE-2026-22248HIGHGLPI affected by Remote Code Execution via malicious uploadEPSS 0.3%CVE-2025-5174MEDIUMerdogant pypickle pypickle.py load deserializationEPSS 0.3%CVE-2026-22384CRITICALWordPress Applay - Shortcodes plugin <= 3.7 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-1286HIGHCWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote cEPSS 0.3%CVE-2023-1145HIGH Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a deserialization vulnerability targeting the DeviEPSS 0.3%CVE-2026-47856MEDIUMJsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-listEPSS 0.3%