Falhas do tipo CWE-502

2.665 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2026-45794HIGHOpenAM Unsafe Java Deserialization via SNSEPSS 0.6%CVE-2025-0724HIGHProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object InjectionEPSS 0.6%CVE-2022-3568HIGHImageMagick Engine <= 1.7.5 - Cross-Site Request Forgery to PHAR DeserializationEPSS 0.6%CVE-2024-29136HIGHWordPress Tourfic plugin <= 2.11.17 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-24661HIGHWordPress Taxi Booking Manager for WooCommerce plugin <= 1.1.8 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-5497MEDIUMslackero phpwcms Feedimport processing.inc.php deserializationEPSS 0.6%CVE-2024-7486HIGHMultiPurpose <= 1.2.0 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-7434HIGHUltraPress <= 1.2.2 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2025-71321CRITICALpicklescan - Arbitrary File Writing via distutils Module BypassEPSS 0.6%CVE-2024-5724HIGHPhoto Video Gallery Master <= 1.5.3 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-2694HIGHBetheme <= 27.5.6 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-10587HIGHFunnelforms Free <= 3.7.5.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2026-12240HIGHExport User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name FieldEPSS 0.6%CVE-2024-6152HIGHFlipbox Builder <= 1.5 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-11501HIGHGallery <= 1.3 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2024-37055HIGHDeserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaEPSS 0.6%CVE-2025-53606CRITICALApache Seata (incubating): Deserialization of untrusted Data in Apache Seata ServerEPSS 0.6%CVE-2025-14071HIGHLive Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output ShortcodeEPSS 0.6%CVE-2023-43981CRITICALPresto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_foldeEPSS 0.6%CVE-2026-10042CRITICALmanga-image-translator RCE via Unsafe Pickle Deserialization in Share ModelEPSS 0.6%