Skip to main content

Threats Tagged 'cwe-303'

View all threats tagged with 'cwe-303'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-303

Threats Tagged 'cwe-303'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat build of Apache Camel 4.18.4 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) * jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision (CVE-2026-10050) * rhaf-camel-spring-boot-maven-repository.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting (CVE-2026-66274) * jetty-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) * sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation (CVE-2026-56624) * cxf-rt-transports-jms: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage (CVE-2026-66909) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider (CVE-2026-68079) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization Code Replay via Race Condition (CVE-2026-57818) * cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation (CVE-2026-57817) * camel: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers (CVE-2026-46457) * camel: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers (CVE-2026-46456) * camel: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields (CVE-2026-48203) * camel-amqp: Apache Camel: Information disclosure via deserialization of untrusted data (CVE-2026-42527) * proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation (CVE-2026-66273) * proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching (CVE-2026-66257) * netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder (CVE-2026-73507) * micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing (CVE-2026-59296) * cxf-rt-rs-security-oauth2: Apache CXF: Security bypass due to improper handling of authorization parameters (CVE-2026-63687) * camel-knative: Apache Camel Knative: Header injection vulnerability allows server-side request forgery (CVE-2026-63621) * camel-main: Apache Camel: Improper authentication allows JWT bypass in Platform HTTP Main component (CVE-2026-66908) * netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration (CVE-2026-62243) * httpclient5-cache: Apache HttpComponents Client: Denial of Service due to connection leak (CVE-2026-64607) * jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * zstd-jni: zstd-jni: Data corruption or denial of service via use-after-free vulnerability (CVE-2026-87825) * zstd-jni: zstd-jni: Use-After-Free vulnerability allows memory corruption and denial of service (CVE-2026-87877) * zstd-jni: zstd-jni: Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect (CVE-2026-87824) * zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795) * zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046) * jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing (CVE-2026-68497) * zstd-jni: zstd-jni: Denial of Service via out-of-bounds read in ZstdDictDecompress (CVE-2026-90560) * bcprov-jdk18on: Bouncy Castle for Java: Denial of Service via quadratic-time escaping of X.500 distinguished names (CVE-2026-58059) * bcprov-jdk18on: Bouncy Castle for Java: Cryptographic signature bypass in RSA PKCS#1 verification (CVE-2026-12860) * zstd-jni: luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing (CVE-2026-90852) * netty-transport-sctp: Netty: Denial of Service via SCTP memory exhaustion (CVE-2026-59902) * camel-mail: Apache Camel: Injected MIME headers can manipulate route behavior (CVE-2026-59230) * netty-handler: Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext (CVE-2026-75595)

Join the discussion

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator's globally configured Jira or Confluence credentials. A network client that can reach the MCP endpoint can invoke Atlassian tools as the operator, including read and write operations available to that account. The advisory traces the vulnerable input and processing flow through UserTokenMiddleware, AtlassianOpaqueTokenVerifier, _get_fetcher, and streamable-http, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

Join the discussion

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted server-first-message containing a controlled salt and low iteration count, then capturing the resulting client proof to perform offline password cracking. This vulnerability is mitigated by TLS, which is standard in production deployments.

Join the discussion

CVE-2026-93394 is a vulnerability in MongoDB Inc.'s C Driver (libmongoc) affecting versions from 2.0.0 up to but not including 2.3.2. The flaw lies in the SCRAM authentication implementation, where the client proceeds with the authentication handshake and sends the client proof even if a nonce mismatch is detected in the server's first message. This could allow a man-in-the-middle attacker to inject a crafted server message and capture the client proof, potentially enabling offline password cracking. The vulnerability is mitigated by the use of TLS, which is standard in production environments.

Join the discussion

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby may be able to view, tamper with, destroy, or delete control programs.

Join the discussion

CVE-2026-73444 is a vulnerability in Arista Networks EOS affecting VRRPv2 IP Authentication Header (IP-AH) authentication. An unauthenticated attacker with access to the layer 2 network segment running VRRP can bypass authentication and assume the virtual router master role. This allows the attacker to intercept, modify, or discard traffic sent to the virtual gateway address. The vulnerability affects specific versions of EOS prior to fixed releases. The CVSS score is 4.7, indicating medium severity with a focus on availability impact.

Join the discussion

On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).

Join the discussion

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

Join the discussion

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

Join the discussion

A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine.

Join the discussion

Showing 1 to 10 of 41 results

Filters:Tag: cwe-303
Page 1 of 5
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses