CWE-130— Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.— MITRE CWE catalog
116 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-130page 3 of 3
- CVE-2026-54466HIGHCVSS 7.5EG 7.52026-07-15
websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence…
- CVE-2026-5706HIGHCVSS 8.9EG 8.92026-08-27
In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must come from a device that has already joined the network. …
- CVE-2026-5766MEDIUMCVSS 5.3EG 5.32026-05-05
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and caus…
- CVE-2026-58096CRITICALCVSS 8.8EG 9.82026-08-26
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 a…
- CVE-2026-58097HIGHCVSS 7.8EG 7.82026-08-26
mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially exe…
- CVE-2026-60060MEDIUMCVSS 6.3EG 6.32026-07-17
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of…
- CVE-2026-62423MEDIUMCVSS 5.5EG 5.52026-07-28
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from…
- CVE-2026-62424MEDIUMCVSS 5.5EG 5.52026-07-28
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from…
- CVE-2026-6432MEDIUMCVSS 5.3EG 5.32026-06-25
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
- CVE-2026-67292MEDIUMCVSS 6.5EG 6.52026-08-01
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to …
- CVE-2026-71337HIGHCVSS 7.8EG 7.82026-09-08
Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.
- CVE-2026-71402MEDIUMCVSS 5.4EG 5.42026-08-27
An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length instead of the length of the remaining UDP payload. Consequentl…
- CVE-2026-73455HIGHCVSS 7.5EG 7.52026-09-16
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
- CVE-2026-81575HIGHCVSS 7.5EG 7.52026-08-27
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data itself. Missing bounds checking on the data length value can lead to out of bounds re…
- CVE-2026-9054CRITICALCVSS 9.2EG 9.22026-05-22
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.
- CVE-2026-90678HIGHCVSS 7.5EG 7.52026-09-13
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic m…
Map vulnerabilities like CWE-130 to your infrastructure
EchelonGraph correlates every CVE — across CWE-130 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →