Falhas do tipo CWE-502

2.654 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2026-3060CRITICALCVE-2026-3060EPSS 1.2%CVE-2024-3070CRITICALLast Viewed Posts by WPBeginner <= 1.0.0 - Unauthenticated PHP Object InjectionEPSS 1.2%CVE-2024-9511CRITICALFluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider <= 2.2.82 - Unauthenticated PHP Object InjectionEPSS 1.2%CVE-2025-53002HIGHLLaMA-Factory Remote Code Execution (RCE) VulnerabilityEPSS 1.2%CVE-2024-1950HIGHProduct Carousel Slider & Grid Ultimate for WooCommerce <= 1.9.7 - Authenticated(Contributor+) PHP Object InjectionEPSS 1.2%CVE-2024-6794CRITICALDeserialization of Untrusted Data in NI VeriStand Waveform Streaming ServerEPSS 1.2%CVE-2024-21217LOWVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: SerialiEPSS 1.1%CVE-2026-77484HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-50222HIGHInductive Automation Ignition ResponseParser Notification Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-50221HIGHInductive Automation Ignition ResponseParser SerializedResponse Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 1.1%CVE-2022-36038HIGHCircuitVerse potential RCE vulnerability via Oj.loadEPSS 1.1%CVE-2024-9701CRITICALRemote Code Execution in kedro-org/kedroEPSS 1.1%CVE-2024-26579CRITICALApache Inlong JDBC VulnerabilityEPSS 1.1%CVE-2024-0668MEDIUMAdvanced Database Cleaner <= 3.1.3 - Authenticated(Administrator+) PHP Object Injection via process_bulk_actionEPSS 1.1%CVE-2022-41779HIGH Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper verification. If the devEPSS 1.1%CVE-2023-2042MEDIUMDataGear JDBC Server deserializationEPSS 1.1%CVE-2022-45185HIGHAn issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can bEPSS 1.1%CVE-2026-41316HIGHERB has an @_init deserialization guard bypass via def_module / def_method / def_classEPSS 1.1%CVE-2024-42363HIGHGHSL-2023-136_SamsonEPSS 1.1%CVE-2024-1856HIGHProgress Telerik Reporting Remote Deserialization VulnerabilityEPSS 1.1%