Falhas do tipo CWE-502

2.657 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2024-2290HIGHAdvanced Ads – Ad Manager & AdSense <= 1.52.1 - Authenticated (Admin+) PHP Object InjectionEPSS 0.9%CVE-2026-50649HIGH.NET Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-28462CRITICALA JNDI rebind operation in the default ORB listener in Payara Server 4.1.2.191 (Enterprise), 5.20.0 and newer (Enterprise), and 5.2020.1 andEPSS 0.9%CVE-2024-0302MEDIUMfhs-opensource iparking vueLogin deserializationEPSS 0.9%CVE-2026-48560MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.9%CVE-2025-22777CRITICALWordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerabilityEPSS 0.9%CVE-2025-43852HIGHGHSL-2025-022_Retrieval-based-Voice-Conversion-WebUIEPSS 0.9%CVE-2026-40858HIGHApache Camel: Camel-Infinispan: Unsafe Deserialization in Remote Aggregation RepositoryEPSS 0.9%CVE-2025-43851HIGHGHSL-2025-021_Retrieval-based-Voice-Conversion-WebUIEPSS 0.9%CVE-2024-24302CRITICALAn issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attaEPSS 0.9%CVE-2024-25117MEDIUMphp-svg-lib lacks path validation on font through SVG inline styles EPSS 0.9%CVE-2022-3525CRITICALDeserialization of Untrusted Data in librenms/librenmsEPSS 0.9%CVE-2025-55010CRITICALKanboard Authenticated Admin Remote Code Execution via Unsafe Deserialization of EventsEPSS 0.9%CVE-2024-9070CRITICALDeserialization Vulnerability in BentoML's Runner Server in bentoml/bentomlEPSS 0.9%CVE-2026-65815HIGHMicrosoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-21226HIGHAzure Core shared client library for Python Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-5671CRITICALInsecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution anEPSS 0.9%CVE-2023-6730CRITICALDeserialization of Untrusted Data in huggingface/transformersEPSS 0.9%CVE-2026-43867CRITICALApache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilterEPSS 0.9%CVE-2023-21568HIGHMicrosoft SQL Server Integration Service (VS extension) Remote Code Execution VulnerabilityEPSS 0.9%