Threats Tagged 'cwe-668'
View all threats tagged with 'cwe-668'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-668'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-50202: CWE-668: Exposure of Resource to Wrong Sphere in SteeltoeOSS Steeltoe.Security.Authentication.CloudFoundryBaseCVE-2026-50202 0 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer prior to version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect prior to version 4.2.0, the JWT signing key cache in `TokenKeyResolver` uses `kid` as the sole cache key without namespacing by authority. In applications with multiple `JwtBearer` schemes pointing to different identity providers, a key fetched for one scheme can satisfy token validation for another. Additionally, cached keys have no expiration, so rotated or revoked keys remain trusted until the application process restarts. Steeltoe.Security.Authentication.CloudFoundryBase version 3.4.0, Steeltoe.Security.Authentication.JwtBearer version 4.2.0, and Steeltoe.Security.Authentication.OpenIdConnect version 4.2.0 patch the issue. If an immediate upgrade is not possible: In multi-scheme deployments, configure only one `JwtBearer` scheme per application when different identity providers are required; and/or restart the application process after an identity provider signing key rotation to clear stale cached keys. Join the discussion | CVE Database V5 | 06/17/2026, 21:53:38 UTC Added: 06/17/2026, 22:35:08 UTC |
CVE-2026-47141: CWE-668: Exposure of Resource to Wrong Sphere in patriksimek vm2CVE-2026-47141 0 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability builtins when they are allowed through require.builtin. The diagnostics_channel, async_hooks, and perf_hooks builtins are not blocked by the dangerous builtin denylist. These modules are process-wide, not sandbox-local. Sandboxed code can use them to observe host application data across the vm2 boundary. This issue has been patched in version 3.11.4. Join the discussion | CVE Database V5 | 06/12/2026, 14:17:35 UTC Added: 06/12/2026, 14:39:31 UTC |
CVE-2026-42535: CWE-668 Exposure of Resource to Wrong Sphere in Apache Software Foundation Apache HTTP ServerCVE-2026-42535 0 A path handling vulnerability exists in the mod_dav_fs module of Apache HTTP Server versions 2.4.67 and earlier. This flaw allows a WebDAV content author to manipulate trusted DAV property databases, which can lead to child process crashes. The issue is resolved in version 2.4.68, and users should upgrade to this version to mitigate the risk. Join the discussion | CVE Database V5 | 06/08/2026, 15:14:49 UTC Added: 06/08/2026, 15:48:51 UTC |
CVE-2025-15653: CWE-668 Exposure of Resource to Wrong Sphere in Dräger Zeus IECVE-2025-15653 0 Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise software integrity via USB interface manipulation. Attackers can exploit the unprotected USB interfaces to impair therapy functions, manipulate device-processed data, or leverage the device as a pivot point for broader network-based attacks when connected to a network or Dräger Service Connect. Join the discussion | CVE Database V5 | 06/02/2026, 21:27:37 UTC Added: 06/02/2026, 21:48:37 UTC |
CVE-2026-46430: CWE-668: Exposure of Resource to Wrong Sphere in xyproto algernonCVE-2026-46430 0 Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553") resolves to ":5553". This vulnerability is fixed in 1.17.7. Join the discussion | CVE Database V5 | 05/26/2026, 16:41:42 UTC Added: 05/26/2026, 17:02:38 UTC |
Showing 1 to 5 of 5 results