Falhas do tipo CWE-502

2.657 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2023-46615MEDIUMWordPress KD Coming Soon Plugin <= 1.7 is vulnerable to PHP Object InjectionEPSS 0.8%CVE-2026-24892HIGHopenITCOCKPIT has Unsafe Deserialization in openITCOCKPIT Changelog HandlingEPSS 0.8%CVE-2025-71364HIGHpicklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._startEPSS 0.8%CVE-2021-32568HIGHDeserialization of Untrusted Data in zmister2016/mrdocEPSS 0.8%CVE-2024-1792HIGHCMB2 <= 2.10.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2026-25917HIGHApache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)EPSS 0.8%CVE-2023-24971HIGHIBM B2B Advanced Communication denial of serviceEPSS 0.8%CVE-2024-13770HIGHPuzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2024-1859HIGHSlider Responsive Slideshow – Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2021-42698HIGHAzeoTech DAQFactoryEPSS 0.8%CVE-2024-3740MEDIUMcym1102 nginxWebUI reload exec deserializationEPSS 0.8%CVE-2024-2025HIGHBuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.20 - Authenticated (Subscriber+) PHP Object Injection in get_simple_requestEPSS 0.8%CVE-2025-58748HIGHDataease H2 data source JDBC URL validation bypass leads to remote code executionEPSS 0.8%CVE-2024-13789CRITICALRavpage <= 2.31 - PHP Object InjectionEPSS 0.8%CVE-2024-2693HIGHLink Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2024-1770HIGHMeta Tag Manager <= 3.0.2 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.8%CVE-2026-18163CRITICALIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.8%CVE-2026-27727HIGHmchange-commons-java: Remote Code Execution via JNDI Reference ResolutionEPSS 0.8%CVE-2026-31072CRITICALThe JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCEPSS 0.8%CVE-2025-69690CRITICALNetgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the EPSS 0.8%