Falhas do tipo CWE-502

2.657 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2025-1077CRITICALRemote Code Execution vulnerability in IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite Weather)EPSS 0.9%CVE-2026-50633HIGHApache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImplEPSS 0.9%CVE-2026-57516HIGHRay < 2.56.0 Unsafe Deserialization RCE via WebDataset ReaderEPSS 0.9%CVE-2024-0603HIGHZhiCms giftcontroller.php deserializationEPSS 0.9%CVE-2023-29006HIGHOrder GLPI plugin vulnerable to remote code execution from authenticated userEPSS 0.9%CVE-2025-0465MEDIUMAquilaCMS categories deserializationEPSS 0.9%CVE-2023-6656MEDIUMDeepFaceLab DFLJPG.py deserializationEPSS 0.9%CVE-2024-5335CRITICALUltimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider <= 1.6.4 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2024-4413CRITICALHotel Booking Lite <= 4.11.1 - Unauthenticated PHP Object InjectionEPSS 0.9%CVE-2025-56422CRITICALA deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.EPSS 0.9%CVE-2022-2561HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of OPC Labs QuickOPC 2022.1. User interactionEPSS 0.9%CVE-2026-70554CRITICALMaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser CookieEPSS 0.9%CVE-2024-1731HIGHAuto Refresh Single Page <= 1.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.9%CVE-2024-1895HIGHEvent Monster <= 1.3.9 - Authenticated(Contributor+) PHP Object Injection via Custom MetaEPSS 0.9%CVE-2026-23946MEDIUMTendenci has Authenticated Remote Code Execution via Pickle DeserializationEPSS 0.9%CVE-2023-38264MEDIUMIBM SDK, Java Technology Edition denial of serviceEPSS 0.8%CVE-2026-76834CRITICALb2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array KeyEPSS 0.8%CVE-2023-49566HIGHApache Linkis DataSource: JDBC Datasource Module with DB2 has JNDI Injection vulnerabilityEPSS 0.8%CVE-2024-36528HIGHnukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in code execution via /adEPSS 0.8%CVE-2023-5391CRITICAL A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted EPSS 0.8%