Falhas do tipo CWE-502

2.669 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2023-51545CRITICALWordPress Job Manager & Career Plugin <= 1.4.4 is vulnerable to Cross Site Request Forgery (CSRF) leading to PHP Object InjectionEPSS 0.3%CVE-2025-67748HIGHFickling has Code Injection vulnerability via pty.spawn()EPSS 0.3%CVE-2025-9191MEDIUMHouzez <= 4.1.6 - Authenticated (Subscriber+) PHP Object Injection via Saved SearchEPSS 0.3%CVE-2026-24156HIGHNVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulneraEPSS 0.3%CVE-2025-13081MEDIUMDrupal core - Moderately critical - Gadget chain - SA-CORE-2025-006EPSS 0.3%CVE-2025-15222LOWDromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserializationEPSS 0.3%CVE-2025-14606LOWtiny-rdm Tiny RDM Pickle Decoding pickle_convert.go pickle.loads deserializationEPSS 0.3%CVE-2026-18490HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2025-43489LOWPoly Clariti Manager - Multiple Security VulnerabilitiesEPSS 0.3%CVE-2025-24794MEDIUMThe Snowflake Connector for Python uses insecure deserialization of the OCSP response cacheEPSS 0.3%CVE-2025-12058MEDIUMVulnerability in Keras Model.load_model Leading to Arbitrary Local File Loading and SSRFEPSS 0.2%CVE-2024-8316HIGHProgress UI for WPF format provider unsafe deserialization vulnerabilityEPSS 0.2%CVE-2024-45857HIGHDeserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl fEPSS 0.2%CVE-2024-34751MEDIUMWordPress Order Export & Order Import for WooCommerce plugin <= 2.4.9 - PHP Object Injection vulnerabilityEPSS 0.2%CVE-2025-10252LOWSEAT Queue Ticket Kiosk Java RMI Registry deserializationEPSS 0.2%CVE-2022-29615—SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The apEPSS 0.2%CVE-2023-46674MEDIUMElasticsearch-hadoop Unsafe DeserializationEPSS 0.2%CVE-2026-17637HIGHIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.2%CVE-2024-37062HIGHDeserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicouslyEPSS 0.2%CVE-2024-37064HIGHDeseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciouslEPSS 0.2%