Threats Tagged 'cwe-1289'
View all threats tagged with 'cwe-1289'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1289'
Click on any threat for detailed analysis and mitigation recommendations
Contrast (Edgeless Systems) through version 1.20.0 has a vulnerability in its imagepuller component where unanchored suffix matching is used for per-registry configuration. This allows configurations intended for a specific registry to also apply to any host whose name ends with the same sequence, including attacker-controlled domains. This can cause the imagepuller to send sensitive authorization headers and trust custom CA bundles or insecure TLS settings to unintended hosts. Image integrity remains protected as image bytes are validated by digest after pull. Configurations using a leading dot in the registry name are not affected. Join the discussion | GCVE Database | 09/27/2026, 03:31:04 UTC Added: 09/27/2026, 04:29:54 UTC |
0 CVE-2026-86831 is a high-severity vulnerability in the aws-network-policy-agent component of Amazon EKS. It involves improper validation of pod identifier uniqueness, which may allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces by crafting pod and namespace names that cause pod identifier collisions. This issue affects versions prior to 1.4.0 of the Network Policy Agent and versions prior to 1.22.4 of the Amazon VPC CNI Managed Add-on. A fix is available in Network Policy Agent 1.4.0 and Amazon VPC CNI Managed Add-on 1.22.4 or later. Join the discussion | CVE Database V5 | 09/16/2026, 19:49:49 UTC Added: 09/16/2026, 20:17:10 UTC |
0 Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction. MPP.Methods.Tempo reserves the pre-broadcast dedup slot on the caller-supplied hex in reserve_hash_atomic/2, keyed through store_key/1 on tx.raw rather than on a canonical form of the transaction. The deserializer stores the caller's hex verbatim and accepts both recovery-id encodings, so one signed transaction submitted once with v=27 and once with v=0 yields two distinct reserve keys, and both pass the reserve and reach the broadcast path. The plug-level credential replay store is deliberately carved out for tempo in lib/mpp/replay.ex, leaving this reserve as the only gate, and the post-broadcast mark writes the canonical hash key that the raw-keyed reserve never reads. What the duplicate submission yields depends on the node: a nonce-reuse rejection fails closed, while a node that answers with the canonical hash for an already-known transaction returns a second valid Payment-Receipt for a single on-chain payment. This issue affects mpp: from 0.2.0 before 0.16.2. Join the discussion | CVE Database V5 | 09/16/2026, 08:24:40 UTC Added: 09/16/2026, 08:32:02 UTC |
0 CVE-2026-89049 is a server-side request forgery (SSRF) vulnerability in the AWS Systems Manager Agent's Session Manager port forwarding functionality. An authenticated user with port-forwarding permission can bypass the remote destination denylist due to improper validation of equivalent address representations. This allows reaching link-local endpoints and potentially obtaining the managed instance's temporary IAM role credentials, enabling actions with those permissions from outside the instance. The vulnerability affects all versions of the SSM Agent prior to 3.3.4851.0. AWS has released version 3.3.4851.0 to address this issue. Until upgraded, restricting the use of the AWS-StartPortForwardingSessionToRemoteHost document by scoping IAM permissions is recommended. Join the discussion | AWS Security Bulletins | 09/10/2026, 18:44:24 UTC Added: 09/10/2026, 19:00:32 UTC |
0 A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) Bug Fix(es) and Enhancement(s): * backport: osbuild-composer from el10 ships el9 google repos (JIRA:RHEL-127068) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/10/2026, 06:06:23 UTC Added: 08/20/2026, 14:08:54 UTC |
0 CVE-2026-76977 is a medium severity vulnerability in SAP UI5's Frame Options Allowlist. The issue arises from insufficient validation of the parent frame's origin against the configured allowlist, allowing an unauthenticated attacker to host a malicious page that can bypass framing restrictions. If an authenticated user visits the attacker's page and interacts with it, the attacker could trick the user into performing unintended actions. The impact is limited to integrity with no confidentiality or availability impact. Join the discussion | CVE Database V5 | 09/08/2026, 00:13:17 UTC Added: 09/08/2026, 00:52:45 UTC |
0 Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings. When you install Red Hat Lightspeed in Satellite locally, you can generate Red Hat Lightspeed recommendations without sending system data to Red Hat services. Join the discussion | GCVE Database | 09/03/2026, 20:43:08 UTC Added: 06/06/2026, 21:13:34 UTC |
CVE-2026-74994 is an incorrect authorization vulnerability in the mod_auth module of the Erlang OTP inets httpd server. When configured with dets or mnesia authentication backends and multiple directory configuration blocks, all directory blocks share a single user/group namespace. This causes a user authorized for one protected directory to be accepted for all other protected directories on the same server instance. The issue affects multiple OTP and inets versions prior to specific fixed releases. Join the discussion | CVE Database V5 | 09/01/2026, 14:45:57 UTC Added: 09/01/2026, 14:53:31 UTC |
URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to be normalized to Form C before it is encoded (RFC 5891), so a label that is not already in NFC is encoded to a different A-label than its normalized form. A label built from the precomposed Devanagari sequence U+0958 U+093E encodes to xn--72b5c without normalization but to xn--11b2fg after NFC normalization, and xn--72b5c does not round-trip back to the original label. Any caller that reads host() from a URI built from untrusted input and uses it for a security decision (an allow or deny list, an SSRF filter, deduplication, a cache key) sees the non-standard label, while a client that fetches the same URL resolves the NFC form, so the check and the fetch can disagree about the host. Join the discussion | CVE Database V5 | 08/31/2026, 17:29:42 UTC Added: 08/31/2026, 17:37:41 UTC |
Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparisons alone (`$y<1 || $y>9999`, `$m<1 || $m>12`, `$d<1 || $d>$days`), and _parse_check stores the numified fields (`$y+0`). Perl truncates a string at the first character that is not an ASCII digit, so a field whose leading characters are ASCII digits numifies to an in-range prefix and satisfies every test: a year field of three ASCII digits followed by U+0664 ARABIC-INDIC DIGIT FOUR numifies to 202, giving the year 0202, and one non-ASCII digit in the month or day field shifts those fields the same way. The hour, minute and second fields match explicit ASCII character classes (`0?[0-9]`, `[0-5][0-9]`) and do not shift, though a non-ASCII digit in a fractional hour or minute field truncates the fraction. Any caller that passes an untrusted character string to ParseDate() or Date::Manip::Date->parse() can get back a date that differs from the string it parsed, with no parse error. Where the parsed date gates logic such as an expiry check or a retention window, the shift goes unnoticed. Join the discussion | CVE Database V5 | 08/05/2026, 00:00:00 UTC Added: 07/30/2026, 14:08:16 UTC |
Showing 1 to 10 of 32 results