Falhas do tipo CWE-502

2.669 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2026-0859MEDIUMTYPO3 CMS Allows Insecure Deserialization via Mailer File SpoolEPSS 0.2%CVE-2025-11739HIGHCWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges wheEPSS 0.2%CVE-2025-40759HIGHA vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP EPSS 0.2%CVE-2025-46738MEDIUMDeserialization of Untrusted DataEPSS 0.2%CVE-2025-30025MEDIUMThe communication protocol used between the server process and the service control had a flaw that could lead to a local privilege escalatioEPSS 0.2%CVE-2025-31935MEDIUMSubnet Solutions PowerSYSTEM Center Deserialization of Untrusted DataEPSS 0.2%CVE-2025-2180MEDIUMCheckov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code ExecutionEPSS 0.2%CVE-2022-1984MEDIUMThis issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versiEPSS 0.2%CVE-2023-32737HIGHA vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do not properly restriEPSS 0.2%CVE-2025-48535HIGHIn assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a lauEPSS 0.2%CVE-2026-24237HIGHNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of EPSS 0.2%CVE-2025-4393MEDIUMMedtronic MyCareLink Patient Monitor Deserialization VulnerabilityEPSS 0.2%CVE-2024-54678HIGHA vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All vEPSS 0.2%CVE-2026-24221HIGHNVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of EPSS 0.2%CVE-2025-41701HIGHBeckhoff: Deserialization of untrusted data by TwinCAT 3 EngineeringEPSS 0.2%CVE-2025-61677LOWDataChain: Deserialization of Untrusted Data from Environment VariablesEPSS 0.2%CVE-2026-24228HIGHNVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploitEPSS 0.2%CVE-2025-48018HIGHDeserialization of Untrusted DataEPSS 0.2%CVE-2025-41700HIGHCODESYS Development System - Deserialization of Untrusted DataEPSS 0.2%CVE-2024-10382HIGHArbitrary Code execution in Car App Android Jetpack LibraryEPSS 0.2%