Falhas do tipo CWE-502

2.630 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2022-40314CRITICALA remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.EPSS 1.7%CVE-2021-37632HIGHDeserialization of Untrusted Data in com.supermartijn642.configlib.ConfigSyncPacketEPSS 1.7%CVE-2022-41237CRITICALJenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a EPSS 1.7%CVE-2021-21866HIGHA unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESEPSS 1.7%CVE-2022-37023Apache Geode deserialization of untrusted data flaw when using REST API on Java 8 or Java 11EPSS 1.7%CVE-2024-49063HIGHMicrosoft/Muzic Remote Code Execution VulnerabilityEPSS 1.7%CVE-2025-32444CRITICALvLLM Vulnerable to Remote Code Execution via Mooncake IntegrationEPSS 1.7%CVE-2022-41875CRITICALRemote Code Execution in OpticaEPSS 1.7%CVE-2023-46279Apache Dubbo: Bypass deny serialize list check in Apache DubboEPSS 1.7%CVE-2023-6654MEDIUMPHPEMS Session Data session.cls.php deserializationEPSS 1.7%CVE-2024-12433CRITICALRemote Code Execution in infiniflow/ragflowEPSS 1.7%CVE-2021-36336CRITICALWyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execuEPSS 1.7%CVE-2021-21867HIGHAn unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESEPSS 1.6%CVE-2022-41137HIGHApache Hive: Deserialization of untrusted data when fetching partitions from the MetastoreEPSS 1.6%CVE-2022-36006HIGHAuthenticated remote code execution due to insecure deserialization (GHSL-2022-063)EPSS 1.6%CVE-2026-25166HIGHWindows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution VulnerabilityEPSS 1.6%CVE-2022-45136CRITICALApache Jena SDB allows arbitrary deserialisation via JDBCEPSS 1.6%CVE-2022-31115HIGHUnsafe YAML deserialization in opensearch-rubyEPSS 1.6%CVE-2020-36727CRITICALNewsletter Manager <= 1.5.1 - Insecure DeserializationEPSS 1.6%CVE-2021-1413MEDIUMCisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Authenticated Remote Code Execution VulnerabilitiesEPSS 1.6%