Falhas do tipo CWE-502

2.669 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2025-53415HIGHFile Parsing Deserialization of Untrusted Data in DTM SoftEPSS 0.2%CVE-2026-2626HIGHDivi Booster < 5.0.2 - Unauthenticated PHP Object InjectionEPSS 0.2%CVE-2025-33241HIGHNVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A EPSS 0.2%CVE-2025-33243HIGHNVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successfulEPSS 0.2%CVE-2024-10013HIGHProgress UI for WinForms format provider unsafe deserialization vulnerabilityEPSS 0.2%CVE-2025-33226HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A sEPSS 0.2%CVE-2025-54886HIGHskops: Card.get_model does not block arbitrary code executionEPSS 0.2%CVE-2023-32736HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16EPSS 0.2%CVE-2024-34274LOWOpenBD 20210306203917-6cbe797 is vulnerable to Deserialization of Untrusted Data. The cookies bdglobals and bdclient_spot of the OpenBD softEPSS 0.2%CVE-2024-49849HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16EPSS 0.2%CVE-2026-1323MEDIUMInsecure Deserialization in extension "Mailqueue" (mailqueue)EPSS 0.2%CVE-2025-7976HIGHAnritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 0.2%CVE-2026-36471MEDIUMDeserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbiEPSS 0.2%CVE-2023-32735HIGHA vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V1EPSS 0.2%CVE-2026-24141HIGHNVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user could cause unsafe deseEPSS 0.2%CVE-2026-24150HIGHNVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciouEPSS 0.2%CVE-2025-33248HIGHNVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load EPSS 0.2%CVE-2026-24152HIGHNVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciouEPSS 0.2%CVE-2026-24151HIGHNVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously craEPSS 0.2%CVE-2025-53393MEDIUMIn Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.EPSS 0.2%