Falhas do tipo CWE-502

2.657 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2026-14637HIGHkirilkirkov Ecommerce-CodeIgniter-Bootstrap ShoppingCart.php getCartItems deserializationEPSS 0.8%CVE-2024-8255HIGHPath Traversal in Ocean Data Systems Dream ReportEPSS 0.8%CVE-2026-16138HIGHRemote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO serviceEPSS 0.8%CVE-2023-46615MEDIUMWordPress KD Coming Soon Plugin <= 1.7 is vulnerable to PHP Object InjectionEPSS 0.8%CVE-2024-8003MEDIUMGo-Tribe gotribe-admin Log routes.go InitRoutes deserializationEPSS 0.8%CVE-2025-71364HIGHpicklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._startEPSS 0.8%CVE-2026-24892HIGHopenITCOCKPIT has Unsafe Deserialization in openITCOCKPIT Changelog HandlingEPSS 0.8%CVE-2021-32568HIGHDeserialization of Untrusted Data in zmister2016/mrdocEPSS 0.8%CVE-2024-1792HIGHCMB2 <= 2.10.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2023-24971HIGHIBM B2B Advanced Communication denial of serviceEPSS 0.8%CVE-2024-13770HIGHPuzzles | WP Magazine / Review with Store WordPress Theme + RTL <= 4.2.4 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2026-41635CRITICALApache MINA: AbstractIoBuffer.resolveClass() null-clazz Branch Skips acceptMatchers Filter — Full Object Deserialization RCEEPSS 0.8%CVE-2026-48207CRITICALApache Fory: PyFory ReduceSerializer Incomplete Policy EnforcementEPSS 0.8%CVE-2024-1859HIGHSlider Responsive Slideshow – Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2021-42698HIGHAzeoTech DAQFactoryEPSS 0.8%CVE-2024-3740MEDIUMcym1102 nginxWebUI reload exec deserializationEPSS 0.8%CVE-2024-2025HIGHBuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages <= 3.4.20 - Authenticated (Subscriber+) PHP Object Injection in get_simple_requestEPSS 0.8%CVE-2025-58748HIGHDataease H2 data source JDBC URL validation bypass leads to remote code executionEPSS 0.8%CVE-2024-2693HIGHLink Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.8%CVE-2024-1770HIGHMeta Tag Manager <= 3.0.2 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.8%