Falhas do tipo CWE-502

2.665 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2026-31239CRITICALThe mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggiEPSS 0.6%CVE-2025-49330CRITICALWordPress Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.3.0 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2024-30227CRITICALWordPress Geo Controller plugin <= 8.6.4 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-21619LOWUnsafe Deserialization of Erlang Terms in hex_coreEPSS 0.6%CVE-2026-7301CRITICALCVE-2026-7301EPSS 0.6%CVE-2025-49507CRITICALWordPress CozyStay theme < 1.7.1 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-67729HIGHlmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()EPSS 0.6%CVE-2024-4838HIGHConvertPlus <= 3.5.26 - Authenticated (Contributor+) PHP Object InjectionEPSS 0.6%CVE-2026-16062MEDIUMEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ ContentEPSS 0.6%CVE-2026-14534HIGHFickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)EPSS 0.6%CVE-2026-24163HIGHNVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successEPSS 0.6%CVE-2025-32571HIGHWordPress TuriTop Booking System Plugin <= 1.0.10 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-60214CRITICALWordPress Goldenblatt theme < 1.3.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-61880HIGHIn Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.EPSS 0.6%CVE-2025-60225CRITICALWordPress BugsPatrol theme <= 1.5.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-10571MEDIUMIBM WebSphere Application Server Liberty is affected by a denial of serviceEPSS 0.6%CVE-2026-35300CRITICALVulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1EPSS 0.6%CVE-2025-32686HIGHWordPress Team Members plugin <= 3.4.4 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2023-32513HIGHWordPress GiveWP Plugin <= 2.25.3 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2026-27776HIGHIM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesignEPSS 0.6%