Threats Tagged 'cwe-672'
View all threats tagged with 'cwe-672'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-672'
Click on any threat for detailed analysis and mitigation recommendations
0 Maravel Framework versions prior to 10.74.0 have a high-severity token replay vulnerability due to a lifecycle mismatch between stateless token validation and relational caching layers. This flaw causes blacklisted JWT tokens to be prematurely evicted from cache, allowing them to be reused for up to 14 days. The issue arises from the tymon/jwt-auth package's use of cache tags with a forced 2-hour eviction ceiling, which truncates the intended 14-day blacklist lifespan. Cache flushes or natural evictions invalidate blacklist records, enabling token replay attacks. The vulnerability is architectural and not fixed by a simple framework upgrade; version 10.74.0 introduces a workaround to decouple token identifiers from tagged caches. Users must apply configuration changes to avoid early cache evictions and ensure token blacklists persist for their full lifespan. Join the discussion | CVE Database V5 | 09/08/2026, 22:17:35 UTC Added: 09/08/2026, 22:22:53 UTC |
0 CVE-2026-61699 affects forgekeep's nebula-mesh, a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, the system's certificate revocation mechanism is flawed, allowing revoked hosts to remain connected and reachable within the mesh for extended periods. This occurs because the blocklist does not propagate to peers' configurations, enabling an attacker with exfiltrated host credentials to bypass revocation and maintain access. The issue has been addressed in version 0.7.1. Join the discussion | CVE Database V5 | 09/04/2026, 19:43:28 UTC Added: 09/04/2026, 19:52:46 UTC |
CVE-2026-19538 is an authentication bypass vulnerability in NLnet Labs NSD version 4.8.0. The issue allows attackers to bypass BLOCKED access control list items on the proxy protocol port by connecting over TCP or TLS and sending the query twice on a kept-open connection. This flaw can lead to unauthorized access despite intended access restrictions. Join the discussion | CVE Database V5 | 09/01/2026, 21:31:25 UTC Added: 08/26/2026, 09:07:43 UTC |
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did not remove subtree entries whose end_height belonged to that block, unlike the cleanup performed by pop_root. When the winning fork later finalized, the abandoned branch's stale subtree data could be written to RocksDB and survive node restarts. The corrupted history can cause z_getsubtreesbyindex consumers such as lightwalletd and light wallets to receive incorrect subtree roots, producing wallet synchronization failures or incorrect wallet state and requiring a full state rebuild for recovery. This issue is fixed in version 4.5.0. Join the discussion | GCVE Database | 08/18/2026, 19:24:44 UTC Added: 07/02/2026, 22:56:53 UTC |
0 BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available. Join the discussion | CVE Database V5 | 08/18/2026, 13:28:28 UTC Added: 08/18/2026, 13:50:00 UTC |
0 Apache CXF's DefaultEncryptingOAuthDataProvider improperly handles revoked access and refresh tokens, allowing them to decrypt successfully and report as active via TokenIntrospectionService. This behavior violates RFC requirements that revoked tokens must be invalidated and introspection must return active:false. The issue affects multiple versions prior to fixed releases. Users are advised to upgrade to versions 4.2.3, 4.1.8, or 3.6.12 where the problem is resolved. Join the discussion | CVE Database V5 | 08/06/2026, 11:22:37 UTC Added: 08/06/2026, 11:56:59 UTC |
0 In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query. Join the discussion | CVE Database V5 | 07/22/2026, 13:05:53 UTC Added: 07/22/2026, 13:22:40 UTC |
0 An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked. Join the discussion | CVE Database V5 | 07/16/2026, 00:00:00 UTC Added: 07/16/2026, 18:48:09 UTC |
0 Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 07/03/2026, 20:35:37 UTC Added: 07/03/2026, 20:52:21 UTC |
0 Scope: Amazon Content Type: Informational Publication Date: 2025/06/12 10:30 AM PDT Description Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on the Amazon Cloud Cam, the device attempts to connect to a remote service infrastructure that has been deprecated due to end-of-life status. The device defaults to a pairing status in which an arbitrary user can bypass SSL pinning to associate the device to an arbitrary network, allowing for network traffic interception and modification. Affected version: All Join the discussion | CVE Database V5 | 06/05/2026, 19:19:25 UTC Added: 06/12/2025, 19:38:34 UTC |
Showing 1 to 10 of 24 results