Falhas do tipo CWE-502

2.665 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2022-45134CRITICALMahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particulaEPSS 0.6%CVE-2025-27287CRITICALWordPress SS Quiz Plugin <= 2.0.5 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-27286CRITICALWordPress Saoshyant Slider Plugin <= 3.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-52207CRITICALWordPress HTML5 MP3 Player with Playlist Free Plugin <= 3.0.0 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2025-32572CRITICALWordPress Kata Plus Plugin <= 1.5.3 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-28782HIGHWordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2025-2689MEDIUMyiisoft Yii2 SortableIterator.php getIterator deserializationEPSS 0.6%CVE-2026-92785CRITICALAngel through 3.3.0 Unauthenticated Kryo Deserialization of Arbitrary ClassesEPSS 0.6%CVE-2025-71342HIGHpicklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcodeEPSS 0.6%CVE-2025-71345HIGHpicklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_profEPSS 0.6%CVE-2025-71359HIGHpicklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loadsEPSS 0.6%CVE-2026-35464HIGHpyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file write to Flask session store and code executionEPSS 0.6%CVE-2025-71341HIGHpicklescan - Remote Code Execution via Undetected profile.Profile.runctxEPSS 0.6%CVE-2025-71349HIGHpicklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickle FilesEPSS 0.6%CVE-2026-44963CRITICALA vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.EPSS 0.6%CVE-2026-78032CRITICALSOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privEPSS 0.6%CVE-2025-66571CRITICALUNA CMS 9.0.0-RC1 - 14.0.0-RC4 PHP Object InjectionEPSS 0.6%CVE-2025-3857HIGHInfinite loop condition in Amazon.IonDotnetEPSS 0.6%CVE-2023-27459HIGHWordPress User Registration plugin <= 2.3.2.1 - Authenticated PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-67579HIGHFilter expression injection via forged keyset pagination cursor in AshEPSS 0.6%