Falhas do tipo CWE-502

2.657 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2026-4851CRITICALGRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserializationEPSS 0.8%CVE-2026-34084CRITICALPhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::loadEPSS 0.8%CVE-2026-64606CRITICALApache Fory, Apache Fory: Class-registration bypass through an auto-admitted SerializedLambda capturing interfaceEPSS 0.8%CVE-2025-11622HIGHInsecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privilegEPSS 0.8%CVE-2026-73699HIGHFileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()EPSS 0.8%CVE-2024-1750MEDIUMTemmokuMVC Image Download images_get_down.php img_replace deserializationEPSS 0.8%CVE-2025-59285HIGHAzure Monitor Agent Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-5085HIGHHash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object InjectionEPSS 0.8%CVE-2024-56180CRITICALApache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code executionEPSS 0.8%CVE-2024-31317HIGHIn multiple functions of ZygoteProcess.java, there is a possible way to achieve code execution as any app via WRITE_SECURE_SETTINGS due to uEPSS 0.8%CVE-2025-30773HIGHWordPress TranslatePress plugin <= 2.9.6 - PHP Object Injection VulnerabilityEPSS 0.8%CVE-2026-81757HIGHWordPress Rank Math SEO plugin <= 1.0.276 - Remote Code Execution (RCE) vulnerabilityEPSS 0.8%CVE-2026-33725HIGHMetabase vulnerable to RCE and Arbitrary File Read via H2 JDBC INIT Injection in EE Serialization ImportEPSS 0.8%CVE-2025-5499MEDIUMslackero phpwcms image_resized.php getimagesize deserializationEPSS 0.8%CVE-2025-30012CRITICALMultiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)EPSS 0.8%CVE-2024-37060HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously craftEPSS 0.8%CVE-2026-7566MEDIUMLearnPress – Backup & Migration Tool <= 4.1.4 - Authenticated (Administrator+) PHP Object Injection via WXR XML File UploadEPSS 0.8%CVE-2024-13410CRITICALCozyStay <= 1.7.0 and TinySalt <= 3.9.0 - Unauthenticated PHP Object Injection in ajax_handlerEPSS 0.8%CVE-2025-2105HIGHJupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAREPSS 0.8%CVE-2025-25691MEDIUMA PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a cEPSS 0.8%