Falhas do tipo CWE-502

2.657 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2024-13789CRITICALRavpage <= 2.31 - PHP Object InjectionEPSS 0.8%CVE-2026-7858CRITICALDeserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026xEPSS 0.8%CVE-2026-11756CRITICALDeserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026xEPSS 0.8%CVE-2026-65883CRITICALJoomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0EPSS 0.8%CVE-2026-39890CRITICALPraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition LoadingEPSS 0.8%CVE-2026-59940CRITICALSeroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserializationEPSS 0.8%CVE-2026-17061CRITICALDeserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026EPSS 0.8%CVE-2026-24747HIGHPyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint FilesEPSS 0.8%CVE-2026-33337HIGHFirebird has a buffer overflow when parsing corrupted slice packetsEPSS 0.8%CVE-2025-2000CRITICALQiskit SDK code executionEPSS 0.8%CVE-2025-69690CRITICALNetgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the EPSS 0.8%CVE-2022-2870MEDIUMlaravel deserializationEPSS 0.8%CVE-2026-5426CRITICALKnowledgeDeliver deployments before February 24, 2026 use a static ASP.NET/IIS machineKey valueEPSS 0.8%CVE-2024-10079HIGHWP Easy Post Types <= 1.4.4 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.8%CVE-2025-45146CRITICALModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. ThiEPSS 0.8%CVE-2026-64608CRITICALApache Fory: Heap type confusion and out-of-bounds read/write in C++ compatible-mode field-skip pathsEPSS 0.8%CVE-2026-61484CRITICALApache Lucy: LucyX::Remote::SearchServer unauthenticated remote Storable::thaw -> RCE/DoSEPSS 0.8%CVE-2024-10932HIGHBackup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'EPSS 0.8%CVE-2022-3291MEDIUMSerialization of sensitive data in GitLab EE affecting all versions from 14.9 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.EPSS 0.8%CVE-2024-8922HIGHProduct Enquiry for WooCommerce <= 2.2.33.33 - Authenticated (Author+) PHP Object Injection in enquiry_detail.phpEPSS 0.8%