Falhas do tipo CWE-502

2.657 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2025-47277CRITICALvLLM Allows Remote Code Execution via PyNcclPipe Communication ServiceEPSS 1.0%CVE-2023-48952HIGHAn issue in the box_deserialize_reusing function in openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS)EPSS 1.0%CVE-2026-58281HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-26215CRITICALmanga-image-translator Shared API Unsafe Deserialization RCEEPSS 1.0%CVE-2025-34414CRITICALEntrust Instant Financial Issuance (IFI) Legacy Remoting Service .NET Remoting RCEEPSS 1.0%CVE-2026-20307CRITICALCisco Identity Services Engine Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-34347CRITICAL​Delta Electronics InfraSuite Device Master Deserialization of Untrusted DataEPSS 1.0%CVE-2026-5127HIGHUser Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Authenticated (Subscriber+) PHP Object InjectionEPSS 1.0%CVE-2023-3259CRITICALThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP addEPSS 1.0%CVE-2026-49286HIGHPhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)EPSS 0.9%CVE-2024-12562CRITICALs2Member Pro <= 241216 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2024-31879HIGHIBM i denial of serviceEPSS 0.9%CVE-2021-22777A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.EPSS 0.9%CVE-2024-53910CRITICALAn issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrarEPSS 0.9%CVE-2024-53915CRITICALAn issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrarEPSS 0.9%CVE-2024-53914CRITICALAn issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrarEPSS 0.9%CVE-2024-53912CRITICALAn issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrarEPSS 0.9%CVE-2024-53911CRITICALAn issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrarEPSS 0.9%CVE-2024-53909CRITICALAn issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrarEPSS 0.9%CVE-2024-53913CRITICALAn issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrarEPSS 0.9%