Threats Tagged 'cwe-1287'
View all threats tagged with 'cwe-1287'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1287'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-80051: CWE-1287 Improper Validation of Specified Type of Input in graphql-go project graphql-goCVE-2026-80051 0 github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) accept input whose type does not match the declared String, ID, or Boolean scalar instead of raising the request error that the GraphQL specification mandates. In some cases (but not any typical case of JSON sent to a website), a deeply nested value leads to an unrecoverable "fatal error: stack overflow" condition. Join the discussion | CVE Database V5 | 08/25/2026, 17:55:57 UTC Added: 08/25/2026, 18:08:00 UTC |
CVE-2026-5304: CWE-1287: Improper Validation of Specified Type of Input in Axis Communications AB AXIS OSCVE-2026-5304 0 An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application. Join the discussion | CVE Database V5 | 08/11/2026, 05:47:49 UTC Added: 08/11/2026, 05:56:58 UTC |
CVE-2026-18830: CWE-1287 Improper validation of specified type of input in AWS Amazon Bedrock AgentCore harnessCVE-2026-18830 0 Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation. Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set. Impacted versions: Amazon Bedrock AgentCore harness InvokeHarness API prior to July 31, 2026. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | CVE Database V5 | 08/20/2026, 21:35:57 UTC Added: 08/04/2026, 17:57:19 UTC |
CVE-2026-9390: CWE-643 Improper Neutralization of Data within XPath Expressions ('XPath Injection') in TIMLEGGE XML::SigCVE-2026-9390 0 XML::Sig versions before 0.71 for Perl are vulnerable to XPath injection due to improper neutralization of data within XPath expressions. The vulnerability arises because the verify() and _get_signed_xml() functions build XPath queries by concatenating unescaped URI values from the document, allowing an attacker to inject arbitrary XPath operators. This can cause the digest verification process to select unintended XML nodes, potentially compromising the integrity verification of signed XML documents. Join the discussion | CVE Database V5 | 08/03/2026, 13:09:40 UTC Added: 08/03/2026, 13:33:39 UTC |
CVE-2026-20498: CWE-1287 Improper Validation of Specified Type of Input in MediaTek, Inc. MediaTek chipsetCVE-2026-20498 0 In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765. Join the discussion | CVE Database V5 | 08/03/2026, 02:06:06 UTC Added: 08/03/2026, 02:48:38 UTC |
Showing 1 to 5 of 5 results