Skip to main content

Threats Tagged 'cwe-610'

View all threats tagged with 'cwe-610'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-610

Threats Tagged 'cwe-610'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19032 is a medium severity vulnerability in FasterXML jackson-databind that involves unsafe reflection via deserialization of java.nio.file.Path from untrusted JSON input. The vulnerability arises because the deserialization process resolves a URI scheme from attacker-controlled input and uses it to select a FileSystemProvider via Java's ServiceLoader mechanism without restricting schemes. While built-in providers do not perform network I/O or mounting, a third-party provider could potentially be triggered, leading to side effects. The issue affects multiple jackson-databind versions from 2.8.0 up to but excluding 3.2.2 in various version ranges. No direct code execution or data confidentiality impact is described, and the impact is bounded by the behavior of the selected FileSystemProvider.

Join the discussion

A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is needed.

Join the discussion

CVE-2026-21810 affects HCL BigFix Quantum Risk Analyzer version 2.0.1.47 and involves a hardcoded external resource reference combined with a lack of binary integrity checks. This vulnerability could allow an attacker with high privileges to modify the binary, potentially leading to unauthorized code changes. The CVSS score is 4.4, indicating a medium severity level. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion

Git for Windows versions prior to 2.55.0.windows.4 contain a vulnerability where a malicious remote Git server can cause the client to initiate outbound SMB connections during clone or fetch operations if transfer.bundleuri=true. This behavior can expose NTLM authentication credentials to an attacker-controlled host. The issue is resolved in version 2.55.0.windows.4.

Join the discussion

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to the input directory and without honoring --no-allow-remote-refs, allowing arbitrary local file reads. This issue is fixed in version 0.62.0.

Join the discussion

A path traversal vulnerability exists in koxudaxi datamodel-code-generator versions 0.59.0 through 0.61.x. The XML Schema parser improperly resolves schemaLocation values outside the input base path, allowing reading of arbitrary local files. This issue is fixed in version 0.62.0.

Join the discussion

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.

Join the discussion

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.

Join the discussion

(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace. This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue.

Join the discussion

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

Join the discussion

Showing 1 to 10 of 16 results

Filters:Tag: cwe-610
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses