Skip to main content

Threats Tagged 'cwe-755'

View all threats tagged with 'cwe-755'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-755

Threats Tagged 'cwe-755'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-105242 is a medium severity vulnerability in Apache log4net affecting versions from 1.2.11 up to but not including 3.5.0. It involves improper handling of exceptional conditions in the aspnet-request pattern converter. When request parameters trigger ASP.NET request validation errors, the logging layout throws an exception causing the appender to discard the entire log event. This allows a sender to suppress logging of their own requests. The issue only affects applications running on ASP.NET for .NET Framework that use the %aspnet-request layout pattern. Upgrading to version 3.5.0 resolves the issue.

Join the discussion

vLLM is an inference and serving engine for large language models. Prior to 0.30.0, structured-output request failures can escape request-scoped validation and reach the EngineCore fatal-error path. A per-request backend mismatch can re-raise a grammar compilation exception, padding produced by the ngram_gpu speculative-decoding mode can pass a negative token to guidance validation, and the Rust frontend can admit empty structured-output values that the Python frontend rejects, allowing ordinary constrained-generation requests to terminate the shared engine. This issue is fixed in version 0.30.0.

Join the discussion

A vulnerability in Apache Thrift Java bindings before version 0.25.0 involves improper handling of exceptional conditions, resulting in missing release of resources after their effective lifetime. This resource management flaw can lead to potential resource exhaustion or denial of service. The issue has been fixed in Apache Thrift version 0.25.0.

Join the discussion

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Join the discussion

Uncaught exception, improper handling of exceptional conditions, improper resource shutdown vulnerability in Apache Thrift D thrift.server.nonblocking.TNonblockingServer. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Join the discussion

Uncaught exception, Improper Handling of Exceptional Conditions vulnerability in Apache Thrift NodeJS bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

Join the discussion

Apache Thrift Java bindings before version 0.25.0 contain a vulnerability involving improper handling of exceptional conditions, resource allocation without limits or throttling, and uncaught exceptions. This can lead to high-impact issues such as resource exhaustion or application instability. The issue is fixed in version 0.25.0, and users are advised to upgrade.

Join the discussion

PyJWT versions from 2.9.0 up to but not including 2.14.0 improperly handle malformed RSA JWK keys within a JWK Set. When a malformed RSA key with incorrect private exponent data is encountered, a built-in Python ValueError is raised and not caught by PyJWT's error handling, causing the entire JWK Set parsing to abort and no keys to be loaded. This can disrupt applications relying on JWK Sets containing multiple keys if one key is malformed.

Join the discussion

CVE-2026-101099 is a medium severity vulnerability in the ag-ui component of the ag-ui-protocol project, specifically affecting version 2026-09-23. The issue involves improper handling of exceptional conditions in the SseParser.kt file of the Kotlin Community SDK. This vulnerability can be triggered remotely without user interaction and requires low privileges to exploit. A fix has been developed but is pending acceptance in a pull request.

Join the discussion

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiation as a fatal application-layer error instead of a recoverable protocol event. The fatal state disables FTP application-layer parsing for the remainder of the TCP flow, so later commands can evade parser-dependent rules and logging; IPS mode instead drops the flow. This issue is fixed in version 8.0.6.

Join the discussion

Showing 1 to 10 of 67 results

Filters:Tag: cwe-755
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses