Falhas do tipo CWE-1395

48 resultados

Dependência de Componente Terceirizado Vulnerável

Ocorre quando uma aplicação depende de uma biblioteca, framework ou componente externo que contém vulnerabilidades conhecidas e não corrigidas. O risco é que qualquer falha de segurança no componente terceirizado se propaga automaticamente para toda aplicação que o utiliza, sem que o desenvolvedor precise fazer nada — basta estar usando a versão afetada.

Exemplo

Uma API Node.js usa a versão 2.5.0 da biblioteca 'express-validator' que tem RCE documentada. Mesmo que o código da API esteja bem escrito, um atacante explora a vulnerabilidade no validator e consegue executar comandos no servidor. O time de desenvolvimento sequer precisava conhecer esse detalhe — a falha está lá, herdada.

Como mitigar

Mantenha sempre um inventário (SBOM) das dependências e suas versões, configure alertas de CVE para components já em uso, aplique patches regularmente, e revise periodicamente quais bibliotecas são realmente necessárias. Ferramentas como 'npm audit', 'pip-audit' ou 'OWASP Dependency-Check' automatizam a detecção.

CVE-2026-3257CRITICALUnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite libraryEPSS 0.4%CVE-2026-58586CRITICALImage::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebpEPSS 0.4%CVE-2024-32753HIGHTYCO Illustra Pro Gen 4 - JQuery versionEPSS 0.4%CVE-2025-61587LOWWeblate integration with Anubis can lead to Open Redirect via redir parameterEPSS 0.4%CVE-2024-45399MEDIUMIndico has a Cross-Site-Scripting during account creationEPSS 0.4%CVE-2024-14031HIGHSereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard libraryEPSS 0.4%CVE-2024-14030HIGHSereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard libraryEPSS 0.4%CVE-2025-40912CRITICALCryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicodeEPSS 0.4%CVE-2024-26293HIGHUnauthenticated Path Traversal affecting Avid NEXISEPSS 0.4%CVE-2022-4976CRITICALArchive::Unzip::Burst from 0.01 through 0.09 for Perl contains a bundled InfoZip library that is affected by several vulnerabilitiesEPSS 0.3%CVE-2025-12220CRITICALBusybox 1.31.1 - Multiple Known VulnerabilitiesEPSS 0.3%CVE-2025-12219CRITICALVulnerable Components in Azure Access OSEPSS 0.3%CVE-2025-11159CRITICALHitachi Vantara Pentaho Data Integration & Analytics - Dependency on Vulnerable Third-Party ComponentEPSS 0.3%CVE-2026-55789HIGHLogto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service ProvidersEPSS 0.3%CVE-2022-4988HIGHAlien::FreeImage versions through 1.001 for Perl contains several vulnerable librariesEPSS 0.3%CVE-2025-40913MEDIUMNet::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflowEPSS 0.3%CVE-2024-6121HIGHNI SystemLink Server Ships Out of Date Redis VersionEPSS 0.3%CVE-2026-60455HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.2%CVE-2025-15444CRITICALCrypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodiumEPSS 0.2%CVE-2026-8993MEDIUMImproper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacksEPSS 0.2%