CWE-697— Incorrect Comparison
The product compares two entities in a security-relevant context, but the comparison is incorrect.— MITRE CWE catalog
166 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-697page 4 of 4
- CVE-2026-26275HIGHCVSS 7.52026-02-19
httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to version 0.0.23 where Digest header verification could incorrectly succeed due to misuse of Rust's `matches!` macro. Specifi…
- CVE-2026-32322MEDIUMCVSS 5.3EG 5.32026-03-13
soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for BN254 and BLS12-381 in soroban-sdk compared values using their raw U256 representation without first reducing modulo the…
- CVE-2026-34210HIGHCVSS 8.1EG 8.12026-03-31
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a val…
- CVE-2026-34574MEDIUMCVSS 5.4EG 5.42026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, crea…
- CVE-2026-35040MEDIUMCVSS 5.3EG 5.32026-04-09
fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options in verify functions can cause certain unin…
- CVE-2026-44196CRITICALCVSS 9.1EG 9.12026-05-12
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authe…
- CVE-2026-44249HIGHCVSS 8.1EG 8.12026-06-08
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in …
- CVE-2026-45567HIGHCVSS 8.3EG 8.32026-06-10
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publica…
- CVE-2026-45569HIGHCVSS 8.1EG 8.12026-06-10
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in …
- CVE-2026-47202CRITICALCVSS 9.3EG 9.32026-05-26
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnera…
- CVE-2026-48032HIGHCVSS 8.3EG 8.32026-06-10
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue …
- CVE-2026-49340HIGHCVSS 8.1EG 8.12026-06-19
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticated Subsonic user (including non-admin) to write playlist M3…
- CVE-2026-55771HIGHCVSS 8.8EG 8.82026-07-13
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead to inco…
- CVE-2026-59890MEDIUMCVSS 6.1EG 6.12026-07-08
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compi…
- CVE-2026-65903MEDIUMCVSS 6.1EG 6.12026-07-23
DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft input containing tags listed in FORBID_TAGS that are also a…
- CVE-2026-9369MEDIUMCVSS 5.3EG 5.32026-05-24
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation o…
Map vulnerabilities like CWE-697 to your infrastructure
EchelonGraph correlates every CVE — across CWE-697 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →