Threats Tagged 'cwe-185'
View all threats tagged with 'cwe-185'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-185'
Click on any threat for detailed analysis and mitigation recommendations
0 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on* event-handler regular expression omits the forward-slash delimiter and whose do-while condition compares the string to itself, so forbidden nested tags are removed only once. An Author-role or higher user can submit solidus-prefixed event-handler markup or nested forbidden tags that survive sanitization. The stored bio is rendered without sufficient output encoding on /author/{username}, in the admin user-management view, and potentially in comment displays, causing attacker-controlled JavaScript to execute when unauthenticated visitors, administrators, or other users view the content. This can expose browser-session data and permit victim-context account actions, defacement, or phishing. This issue is fixed in version 1.0.8.5. Join the discussion | CVE Database V5 | 09/17/2026, 21:47:20 UTC Added: 09/17/2026, 22:12:12 UTC |
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadly than intended. This vulnerability (CVE-2026-88021) is fixed in Consul 2.0.4 and Consul Enterprise 1.21.18, 1.22.12 and 2.0.4. Join the discussion | CVE Database V5 | 09/10/2026, 18:58:26 UTC Added: 09/10/2026, 19:17:16 UTC |
Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to .netlify/v1/config.json under images.remote_images for Netlify's Image CDN allowlist. In packages/integrations/netlify/src/index.ts, remotePatternToRegex() escapes dots in hostname values but interpolates literal pathname values without escaping regular expression metacharacters such as ., +, ?, (, and [, so a restrictive pathname such as /img/v1.0/file also matches metacharacter-adjacent paths, including paths that cross a segment. Netlify enforces the generated regular expression directly and Astro's matchPattern() helper does not revalidate the request, allowing optimization of images on an already-allowed host that the declared pathname was intended to exclude. This issue is fixed in version 8.1.2. Join the discussion | CVE Database V5 | 08/12/2026, 20:41:10 UTC Added: 08/12/2026, 21:13:14 UTC |
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule — such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses — do not match the normalized rule entry, causing the rule to be silently skipped. This vulnerability is fixed in 4.12.21. Join the discussion | CVE Database V5 | 05/28/2026, 15:29:08 UTC Added: 05/28/2026, 16:48:44 UTC |
CVE-2026-4296 is a high-severity vulnerability in GitHub Enterprise Server involving an incorrect regular expression that allowed bypassing OAuth redirect URI validation. An attacker who knows a legitimate OAuth application's callback URL could craft a malicious authorization link to redirect OAuth authorization codes to attacker-controlled domains. This could enable unauthorized access to victim accounts with the OAuth application's granted scopes. The issue affects all GitHub Enterprise Server versions prior to 3.21 and was fixed in versions 3.20.1 and later. No known exploits in the wild have been reported. Join the discussion | CVE Database V5 | 04/21/2026, 22:12:45 UTC Added: 04/21/2026, 22:31:06 UTC |
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a match if the pattern matches anywhere in the string, so common unanchored patterns (including examples in tekton documentation) can be bypassed by attacker-controlled source strings that contain the trusted pattern as a substring. This can cause an unintended policy match and change which verification mode/keys apply. Versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1 fix the issue. Join the discussion | CVE Database V5 | 04/21/2026, 16:05:43 UTC Added: 04/21/2026, 16:31:11 UTC |
0 league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2. Join the discussion | CVE Database V5 | 03/24/2026, 19:26:23 UTC Added: 03/24/2026, 19:46:16 UTC |
CVE-2026-27895 is a medium severity vulnerability in LDAP Account Manager (LAM) versions prior to 9.5, where the PDF export component improperly validates uploaded file extensions. This flaw allows attackers with limited privileges to upload arbitrary file types, including executable PHP files, potentially leading to remote code execution as the web server user. The vulnerability arises from an incorrect regular expression validation (CWE-185) that fails to restrict file uploads properly. Although no known exploits are currently in the wild, successful exploitation could compromise the integrity of affected systems. The issue is fixed in LAM version 9.5, and a recommended workaround is to make the configuration directory read-only for the web server user. Organizations using LAM for LDAP management should prioritize upgrading or applying mitigations to prevent exploitation. Join the discussion | CVE Database V5 | 03/17/2026, 23:51:26 UTC Added: 03/18/2026, 00:13:21 UTC |
0 fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (<, >, &, ", ') with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5. Join the discussion | CVE Database V5 | 02/20/2026, 20:57:48 UTC Added: 02/20/2026, 21:17:14 UTC |
CVE-2026-25479 is a medium-severity vulnerability in the litestar ASGI framework versions prior to 2.20.0. It arises from improper handling of allowlist host entries, where regex metacharacters are not escaped, allowing attackers to bypass intended hostname restrictions by supplying crafted host headers that match the regex but are not legitimate hosts. This can lead to partial confidentiality and integrity impacts without requiring authentication or user interaction. The vulnerability is fixed in litestar version 2.20.0. European organizations using vulnerable litestar versions in web applications may face risks of host header attacks, potentially enabling unauthorized access or manipulation of application behavior. Mitigation involves upgrading to version 2. Join the discussion | CVE Database V5 | 02/09/2026, 18:48:19 UTC Added: 02/09/2026, 19:31:19 UTC |
Showing 1 to 10 of 13 results