Falhas do tipo CWE-502

2.661 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2024-10962HIGHMigration, Backup, Staging – WPvivid <= 0.9.107 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2026-24157HIGHNVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploEPSS 0.7%CVE-2025-0428HIGHAI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_export_promptsEPSS 0.7%CVE-2025-34153CRITICALHyland OnBase < 17.0.2.87 .NET Remoting TCP Channel Unauthenticated RCEEPSS 0.7%CVE-2025-0429HIGHAI Power: Complete AI Pack <= 1.8.96 - Authenticated (Admin+) PHP Object Injection via wpaicg_export_ai_formsEPSS 0.7%CVE-2020-37071CRITICALCraftCMS 3 vCard Plugin 1.0.0 - Remote Code ExecutionEPSS 0.7%CVE-2026-96560CRITICALLightLLM through 1.2.0 Unauthenticated Remote Code Execution via NCCL PD RPyC Control ChannelEPSS 0.7%CVE-2026-3357HIGHIBM Langflow Desktop FAISS Vector Store Remote Code Execution via malicious Pickle fileEPSS 0.7%CVE-2026-76395HIGHRemote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI ToolkitEPSS 0.7%CVE-2026-9291HIGHInsecure Deserialization in Amazon Braket SDK Job Results ProcessingEPSS 0.6%CVE-2026-65617HIGHPotential remote code execution on an Artifactory package service container.EPSS 0.6%CVE-2026-41731HIGHIn Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserializationEPSS 0.6%CVE-2024-24797CRITICALWordPress ERE Recently Viewed Plugin <= 1.3 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2024-1432MEDIUMDeepFaceLab main.py apply_xseg deserializationEPSS 0.6%CVE-2025-15672HIGHChama < 1.0.13 - Unauthenticated PHP Object InjectionEPSS 0.6%CVE-2023-52181CRITICALWordPress Theme per user Plugin <= 1.0.1 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2025-2566CRITICALDeserialization of Untrusted Data in Kaleris Navis N4EPSS 0.6%CVE-2024-43141CRITICALWordPress Participants Database plugin <= 2.5.9.2 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2024-30223CRITICALWordPress ARMember plugin <= 4.0.26 - Unauthenticated PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-52218CRITICALWordPress WooCommerce Tranzila Gateway Plugin <= 1.0.8 is vulnerable to PHP Object InjectionEPSS 0.6%