Falhas do tipo CWE-502

2.665 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2025-32283HIGHWordPress Solar Energy theme <= 3.5 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2024-26289CRITICALRemote Code Inclusion Vulnerability in Multiple PMB VersionsEPSS 0.6%CVE-2022-44558CRITICALThe AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilEPSS 0.6%CVE-2022-44559CRITICALThe AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilEPSS 0.6%CVE-2024-28777HIGHIBM Cognos Controller code executionEPSS 0.6%CVE-2022-44562CRITICALThe system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may EPSS 0.6%CVE-2024-30222HIGHWordPress ARMember plugin <= 4.0.26 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-10771MEDIUMjeecgboot JimuReport DB2 JDBC testConnection deserializationEPSS 0.6%CVE-2024-6943MEDIUMZhongBangKeJi CRMEB CopyTaobaoServices.php downloadImage deserializationEPSS 0.6%CVE-2026-87930CRITICALMaxSite CMS through 109.6 PHP Object Injection via ci_sessionEPSS 0.6%CVE-2026-83803HIGHSentry: Unsafe pickle deserialization in Relocation FeatureEPSS 0.6%CVE-2023-35815LOWDevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.EPSS 0.6%CVE-2026-15976CRITICALCVE-2026-15976EPSS 0.6%CVE-2023-35814LOWDevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.EPSS 0.6%CVE-2025-26900CRITICALWordPress Flexmls® IDX Plugin Plugin <= 3.14.27 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2023-40555HIGHWordPress Flatsome Theme <= 3.17.5 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2026-28138HIGHWordPress uListing plugin <= 2.2.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2024-13136MEDIUMwangl1989 mysiteforme ShiroConfig.java rememberMeManager deserializationEPSS 0.6%CVE-2026-35537LOWAn issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may leadEPSS 0.6%CVE-2024-4471HIGH140+ Widgets | Best Addons For Elementor – FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%