Falhas do tipo CWE-502

2.654 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2024-45733HIGHRemote Code Execution (RCE) due to insecure session storage configuration in Splunk Enterprise on WindowsEPSS 1.1%CVE-2021-27277HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure MonitoEPSS 1.1%CVE-2025-2244CRITICALInsecure PHP deserialization issue in GravityZone Console (VA-12634)EPSS 1.1%CVE-2022-46478CRITICALThe RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrEPSS 1.1%CVE-2024-24926HIGHWordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object InjectionEPSS 1.1%CVE-2025-14931CRITICALHugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-1196HIGHAdvanced Custom Fields - Contributor+ PHP Object InjectionEPSS 1.1%CVE-2024-53247HIGHRemote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway appEPSS 1.1%CVE-2026-25873CRITICALOmniGen2-RL Reward Server Unsafe Deserialization RCEEPSS 1.1%CVE-2024-8030CRITICALUltimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 2.0.3 - Unauthenticated PHP Object InjectionEPSS 1.1%CVE-2025-27511HIGHGeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store ConnectionEPSS 1.1%CVE-2026-51947CRITICALAn issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_2026EPSS 1.1%CVE-2024-52430CRITICALWordPress Lis Video Gallery plugin <= 0.2.1 - PHP Object Injection vulnerabilityEPSS 1.1%CVE-2026-43633CRITICALHestiaCP 1.9.0-1.9.4 Deserialization RCE via Web TerminalEPSS 1.1%CVE-2021-22097In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a bodyEPSS 1.1%CVE-2023-33284HIGHMarval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to EPSS 1.1%CVE-2026-55175HIGHSpinnaker: Improper yaml processing on kustomize bake operationsEPSS 1.1%CVE-2025-59245CRITICALMicrosoft SharePoint Online Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2022-40889CRITICALPhpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.EPSS 1.1%CVE-2021-22095In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new StrinEPSS 1.1%