Falhas do tipo CWE-502

2.653 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2020-7528A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbEPSS 1.4%CVE-2025-30378HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 1.4%CVE-2025-56816HIGHDatart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrEPSS 1.4%CVE-2026-63516MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.3%CVE-2024-39705CRITICALNLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download funEPSS 1.3%CVE-2023-33963CRITICALDataEase data source has deserialization vulnerabilityEPSS 1.3%CVE-2020-12525HIGHWAGO/M&M Software Deserialization of untrusted data in fdtCONTAINER componentEPSS 1.3%CVE-2019-17635Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is reEPSS 1.3%CVE-2017-20189CRITICALIn Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relEPSS 1.3%CVE-2024-12044CRITICALRemote Code Execution by Pickle Deserialization in open-mmlab/mmdetectionEPSS 1.3%CVE-2024-42362HIGHGHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/importEPSS 1.3%CVE-2024-8862MEDIUMh2oai h2o-3 JDBC Connection 1 getConnectionSafe deserializationEPSS 1.3%CVE-2025-30384HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 1.3%CVE-2025-7384CRITICALDatabase for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File DeletionEPSS 1.3%CVE-2021-28254CRITICALA deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.EPSS 1.3%CVE-2023-38155HIGHAzure DevOps Server Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-62912MEDIUMMicrosoft Exchange Server Denial of Service VulnerabilityEPSS 1.3%CVE-2026-0764CRITICALGPT Academic upload Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-0763CRITICALGPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 1.3%CVE-2022-39256CRITICALOrckestra C1 CMS's deserialization of untrusted data allows for arbitrary code execution.EPSS 1.3%