CWE-502 可信数据的反序列化 类弱点 2189 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }
private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }
try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-24142 | NVIDIA TRT-LLM 代码问题漏洞 — TensorRT-LLM | 6.3 | Medium | 2026-05-20 |
| CVE-2025-33255 | NVIDIA TRT-LLM 代码问题漏洞 — TensorRT-LLM | 7.5 | High | 2026-05-20 |
| CVE-2026-7637 | WordPress plugin Boost 代码问题漏洞 — Boost | 9.8 | Critical | 2026-05-20 |
| CVE-2026-6009 | Jaspersoft Reports Library 代码问题漏洞 — JasperReports Library Community Edition | - | - | 2026-05-19 |
| CVE-2026-43633 | HestiaCP 代码问题漏洞 — hestiacp | 10.0 | Critical | 2026-05-19 |
| CVE-2026-46725 | TYPO3 Extension Content Element Selector 代码问题漏洞 — Extension "Content Element Selector" | - | - | 2026-05-19 |
| CVE-2026-8727 | TYPO3 Extension Site Crawler 代码问题漏洞 — Extension "Site Crawler" | - | - | 2026-05-19 |
| CVE-2026-33233 | AutoGPT 代码注入漏洞 — AutoGPT | 7.6 | High | 2026-05-19 |
| CVE-2026-26978 | FreePBX 代码问题漏洞 — security-reporting | - | - | 2026-05-18 |
| CVE-2026-8751 | H2O 输入验证错误漏洞 — h2o-3 | 7.3 | High | 2026-05-17 |
| CVE-2026-8735 | oinone-pamirs 输入验证错误漏洞 — Pamirs | 6.3 | Medium | 2026-05-17 |
| CVE-2026-44501 | DataHub 代码问题漏洞 — datahub | 4.3 | Medium | 2026-05-14 |
| CVE-2026-1184 | GitLab 代码问题漏洞 — GitLab | 6.5 | Medium | 2026-05-14 |
| CVE-2026-41957 | F5 BIG-IP和F5 BIG-IQ 代码问题漏洞 — BIG-IP | 8.8 | High | 2026-05-13 |
| CVE-2026-7635 | WordPress plugin coreActivity 代码问题漏洞 — coreActivity: Activity Logging for WordPress | 8.1 | High | 2026-05-13 |
| CVE-2026-34659 | Adobe Connect 代码问题漏洞 — Adobe Connect | 9.6 | Critical | 2026-05-12 |
| CVE-2026-40357 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-05-12 |
| CVE-2026-33110 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-05-12 |
| CVE-2026-33112 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-05-12 |
| CVE-2026-40368 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.0 | High | 2026-05-12 |
| CVE-2026-35439 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2026-05-12 |
| CVE-2026-3048 | Sonatype Nexus Repository Manager 代码问题漏洞 — Nexus Repository | - | - | 2026-05-11 |
| CVE-2026-44126 | SEPPmail Secure Email Gateway 代码问题漏洞 — Secure Email Gateway | 9.8AI | Critical AI | 2026-05-08 |
| CVE-2026-5127 | WordPress plugin User Frontend 代码问题漏洞 — User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration | 8.8 | High | 2026-05-08 |
| CVE-2026-41586 | Hyperledger Fabric 代码问题漏洞 — fabric | 8.8AI | High AI | 2026-05-07 |
| CVE-2026-34084 | PhpSpreadsheet 代码问题漏洞 — PhpSpreadsheet | 9.1 | - | 2026-05-05 |
| CVE-2026-7712 | MindsDB 输入验证错误漏洞 — MindsDB | 6.3 | Medium | 2026-05-03 |
| CVE-2026-7647 | WordPress plugin Profile Builder Pro 代码问题漏洞 — Profile Builder Pro | 8.1 | High | 2026-05-02 |
| CVE-2026-7597 | mem0 输入验证错误漏洞 — mem0 | 6.3 | Medium | 2026-05-01 |
| CVE-2026-42778 | Apache MINA 代码问题漏洞 — Apache MINA | 9.8 | Critical | 2026-05-01 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 2189 条 CVE 漏洞。