Falhas do tipo CWE-502

2.648 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2025-27520CRITICALBentoML Allows Remote Code Execution (RCE) via Insecure DeserializationEPSS 40.6%CVE-2026-12569CRITICALRemote Code Execution (RCE) vulnerability in Windchill PDMlinkEPSS 40.6%KEVCVE-2024-1800CRITICALProgress Telerik Report Server DeserializationEPSS 40.4%CVE-2024-32030HIGHRemote code execution via JNDI resolution in JMX metrics collection in Kafka UIEPSS 39.4%CVE-2024-28988CRITICALSolarWinds Web Help Desk Java Deserialization Remote Code Execution VulnerabilityEPSS 39.4%CVE-2023-36050HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 39.2%CVE-2023-49442CRITICALDeserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POSEPSS 38.5%CVE-2022-21647HIGHDeserialization of Untrusted Data in Codeigniter4EPSS 37.7%CVE-2023-36757HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 36.9%CVE-2020-17144HIGHMicrosoft Exchange Remote Code Execution VulnerabilityEPSS 36.5%KEVCVE-2024-43464HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 36.3%CVE-2022-31199CRITICALRemote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix AuditoEPSS 36.0%KEVCVE-2022-23450A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versionsEPSS 35.7%CVE-2023-37941MEDIUMApache Superset: Metadata db write access can lead to remote code executionEPSS 35.5%CVE-2026-45484HIGHMicrosoft SharePoint Elevation of Privilege VulnerabilityEPSS 35.2%CVE-2025-71260HIGHBMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEEPSS 34.4%CVE-2023-1650CRITICALChatBot < 4.4.7 - Unauthenticated PHP Object InjectionEPSS 34.4%CVE-2024-1651CRITICALTorrentpier 2.4.1 - RCEEPSS 34.2%CVE-2026-20131CRITICALCisco Secure Firewall Management Center Software Remote Code Execution VulnerabilityEPSS 33.4%KEVCVE-2026-33112HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 32.7%