Skip to main content

CWE archive

CWE-130 CVEs

Programmatic archive

104 CVEs tagged with CWE-1304 Critical, 53 High, 46 Medium, 1 Low, 0 Unrated.

CVE-2026-62424

Published Jul 28, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfs…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62423

Published Jul 28, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfs…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-26081

Published Jul 20, 2026

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-54466

Published Jul 17, 2026

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that all…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-48487

Published Jul 17, 2026

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advan…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-60060

Published Jul 17, 2026

Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-47692

Published Jun 26, 2026

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator em…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6432

Published Jun 25, 2026

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-45681

Published Jun 2, 2026

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-b…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45615

Published May 29, 2026

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48685

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-9054

Published May 22, 2026

An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-42216

Published May 7, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.…

CVSS 8.8 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-43125

Published May 6, 2026

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and com…

CVSS 9.8 · Critical
evidence mentions
19
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-5766

Published May 5, 2026

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE`…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-33846

Published May 4, 2026

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragme…

CVSS 7.5 · High
evidence mentions
21
Buzz score
46.5

CVE-2026-35547

Published Apr 30, 2026

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the boun…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3868

Published Apr 27, 2026

An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Because of improper validation of length parameters in the HT…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-41898

Published Apr 24, 2026

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, se…

CVSS 8.3 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-31635

Published Apr 24, 2026

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes auth_len from the pac…

CVSS 7.5 · High
evidence mentions
7
Buzz score
37.3
Vendor/product tagsBeta · best-effort

CVE-2026-5367

Published Apr 24, 2026

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client…

CVSS 8.6 · High
evidence mentions
14
Buzz score
40.1

CVE-2026-5265

Published Apr 24, 2026

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self…

CVSS 6.5 · Medium
evidence mentions
13
Buzz score
37.9

CVE-2026-41035

Published Apr 16, 2026

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka -…

CVSS 7.4 · High
evidence mentions
30
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-33555

Published Apr 13, 2026

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is cl…

CVSS 4.0 · Medium
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2026-40199

Published Apr 10, 2026

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 104 CVEsPage 1 of 5