CWE-134— Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.— MITRE CWE catalog
404 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-134page 9 of 9
- CVE-2026-69395MEDIUMCVSS 6.5EG 6.52026-09-08
Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.
- CVE-2026-73782HIGHCVSS 8.8EG 8.82026-09-01
A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a priv…
- CVE-2026-7835LOWCVSS 3.1EG 3.12026-05-21
A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.
- CVE-2026-81574HIGHCVSS 8.2EG 8.22026-08-27
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sens…
Map vulnerabilities like CWE-134 to your infrastructure
EchelonGraph correlates every CVE — across CWE-134 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →