CWE-502 可信数据的反序列化 类弱点 2189 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }
private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }
try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-65493 | Dokan Pro 反序列化注入漏洞 — Dokan Pro | 7.5 | High | 2026-07-23 |
| CVE-2026-59544 | Thrive Themes Thrive Quiz Builder 反序列化注入漏洞 — Thrive Quiz Builder | 9.8 | Critical | 2026-07-23 |
| CVE-2026-13190 | Progress Software Progress Telerik UI for AJAX 反序列化注入漏洞 — Telerik UI for ASP.NET AJAX | 8.1 | High | 2026-07-22 |
| CVE-2026-13185 | Progress Software Progress Telerik UI for AJAX 反序列化注入漏洞 — Telerik UI for ASP.NET AJAX | 8.1 | High | 2026-07-22 |
| CVE-2026-24232 | NVIDIA Tranformers4Rec 反序列化注入漏洞 — Tranformers4Rec | 4.3 | Medium | 2026-07-21 |
| CVE-2026-64606 | Apache Fory 反序列化注入漏洞 — Apache Fory | - | - | 2026-07-21 |
| CVE-2026-63767 | kvcache-ai KTransformers 反序列化注入漏洞 — ktransformers | 9.8 | Critical | 2026-07-20 |
| CVE-2026-28220 | Wazuh 反序列化注入漏洞 — wazuh | 8.4 | High | 2026-07-20 |
| CVE-2026-12484 | Keras 反序列化注入漏洞 — keras-team/keras | - | - | 2026-07-19 |
| CVE-2026-8476 | IBM Langflow OSS 反序列化注入漏洞 — Langflow OSS | 9.9 | Critical | 2026-07-17 |
| CVE-2026-45162 | Pimcore 反序列化注入漏洞 — pimcore | 8.0 | High | 2026-07-17 |
| CVE-2026-15008 | WordPress Uncanny Automator 反序列化注入漏洞 — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | 8.1 | High | 2026-07-16 |
| CVE-2026-24227 | NVIDIA TensorRT 反序列化注入漏洞 — TensorRT | 5.3 | Medium | 2026-07-14 |
| CVE-2026-24220 | NVIDIA TensorRT-LLM 反序列化注入漏洞 — TensorRT-LLM | 6.4 | Medium | 2026-07-14 |
| CVE-2026-47472 | NVIDIA TensorRT-LLM 反序列化注入漏洞 — TensorRT-LLM | 7.8 | High | 2026-07-14 |
| CVE-2026-24233 | NVIDIA TensorRT-LLM 反序列化注入漏洞 — TensorRT-LLM | 8.4 | High | 2026-07-14 |
| CVE-2026-50649 | Microsoft .NET 反序列化注入漏洞 — .NET 8.0 | 7.8 | High | 2026-07-14 |
| CVE-2026-45077 | Symfony 反序列化注入漏洞 — symfony | - | - | 2026-07-14 |
| CVE-2026-55944 | Microsoft Dynamics NAV 2018 反序列化注入漏洞 — Microsoft Dynamics NAV 2018 | 9.8 | Critical | 2026-07-14 |
| CVE-2026-50509 | Microsoft Windows Wireless Wide Area Network Service 反序列化注入漏洞 — Windows 10 Version 1607 | 7.8 | High | 2026-07-14 |
| CVE-2026-50652 | Microsoft Azure Active Directory 反序列化注入漏洞 — Azure Active Directory | 7.5 | High | 2026-07-14 |
| CVE-2026-58644 | Microsoft Office Sharepoint Server 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 9.8 | Critical | 2026-07-14 |
| CVE-2026-50522 | Microsoft Office Sharepoint Server 反序列化注入漏洞 — Microsoft SharePoint Enterprise Server 2016 | 9.8 | Critical | 2026-07-14 |
| CVE-2026-54118 | Microsoft SQL Server 反序列化注入漏洞 — Microsoft SQL Server 2016 Service Pack 3 (GDR) | 9.8 | Critical | 2026-07-14 |
| CVE-2026-54117 | Microsoft SQL Server 反序列化注入漏洞 — Microsoft SQL Server 2025 (CU 6) | 9.8 | Critical | 2026-07-14 |
| CVE-2026-55009 | Microsoft Exchange Server 反序列化注入漏洞 — Microsoft Exchange Server 2016 Cumulative Update 23 | 7.8 | High | 2026-07-14 |
| CVE-2026-58233 | SAP Change and Transport System Attach Tool 反序列化注入漏洞 — SAP Change and Transport System Attach Tool (ctsattach) | 7.6 | High | 2026-07-14 |
| CVE-2026-59518 | wpWax Directorist 反序列化注入漏洞 — Directorist | 9.8 | Critical | 2026-07-13 |
| CVE-2026-59521 | shapedplugin real testimonials 反序列化注入漏洞 — Real Testimonials | 7.2 | High | 2026-07-13 |
| CVE-2026-57738 | ThemeREX 777 反序列化注入漏洞 — 777 | 9.8 | Critical | 2026-07-13 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 2189 条 CVE 漏洞。