CWE-670
133 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-670page 3 of 3
- CVE-2024-53269MEDIUMCVSS 4.5EG 4.52024-12-18
Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4,…
- CVE-2024-53270HIGHCVSS 7.5EG 7.52024-12-18
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_r…
- CVE-2024-53271HIGHCVSS 7.1EG 7.12024-12-18
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been address…
- CVE-2024-5659MEDIUMCVSS 6.5EG 6.52024-06-14
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the…
- CVE-2024-8811HIGHCVSS 7.8EG 7.82024-11-22
WinZip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User interaction is required to exploit this vulnerability in t…
- CVE-2025-21607HIGHCVSS 7.5EG 7.52025-01-14
Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amou…
- CVE-2025-24800CRITICALCVSS 9.3EG 0.02025-01-28
Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability. A critical vulnerability was discovered in the ismp-grandpa crate, that allowed a malicious prover easily convince the verifier of the finality of ar…
- CVE-2025-2886MEDIUMCVSS 4.5EG 4.52025-03-27
Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an incorrect source, alteri…
- CVE-2025-29312CRITICALCVSS 9.1EG 9.12025-03-24
An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.
- CVE-2025-32942HIGHCVSS 7.2EG 7.22025-10-02
SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.
- CVE-2025-32996MEDIUMCVSS 4.0EG 4.02025-04-15
In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.
- CVE-2025-33199LOWCVSS 3.2EG 3.22025-11-25
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successful exploit of this vulnerability might lead to data tampering.
- CVE-2025-38291MEDIUMCVSS 5.5EG 5.52025-07-10
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash Currently, we encounter the following kernel call trace when a firmware crash occurs. This h…
- CVE-2025-43359CRITICALCVSS 9.8EG 9.82025-09-15
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. A UDP server socket…
- CVE-2025-49091HIGHCVSS 8.2EG 8.22025-06-11
KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or…
- CVE-2025-58136HIGHCVSS 7.5EG 7.52026-04-02
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which…
- CVE-2026-20171MEDIUMCVSS 6.8EG 6.82026-05-20
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to tr…
- CVE-2026-34946HIGHCVSS 7.5EG 7.52026-04-09
Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill instruction can result in a host panic. This means that a v…
- CVE-2026-35343LOWCVSS 3.3EG 3.32026-04-22
The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify the only_delimited flag in the cut_fields_newline_char_delim …
- CVE-2026-35387LOWCVSS 3.1EG 3.12026-04-02
OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.
- CVE-2026-35414MEDIUMCVSS 4.2EG 4.22026-04-02
OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.
- CVE-2026-38361HIGHCVSS 7.5EG 7.52026-05-08
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_u…
- CVE-2026-40200HIGHCVSS 8.1EG 8.12026-04-10
An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven mil…
- CVE-2026-40394MEDIUMCVSS 4.0EG 4.02026-04-12
Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 tra…
- CVE-2026-40396MEDIUMCVSS 4.0EG 4.02026-04-12
Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linge…
- CVE-2026-40719HIGHCVSS 7.5EG 7.52026-04-15
Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.
- CVE-2026-40942MEDIUMCVSS 6.3EG 6.32026-04-21
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter)…
- CVE-2026-40960HIGHCVSS 8.1EG 8.12026-04-16
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HT…
- CVE-2026-41527MEDIUMCVSS 6.9EG 6.92026-04-21
KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.
- CVE-2026-41988LOWCVSS 3.2EG 3.22026-04-23
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
- CVE-2026-44928LOWCVSS 2.9EG 2.92026-05-08
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
- CVE-2026-48844HIGHCVSS 7.5EG 7.52026-05-25
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.)
- CVE-2026-6608MEDIUMCVSS 5.3EG 5.32026-04-20
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incorrect control flow. The attack can be launched remotely. The …
Map vulnerabilities like CWE-670 to your infrastructure
EchelonGraph correlates every CVE — across CWE-670 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →