Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-76'

View all threats tagged with 'cwe-76'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-76

Threats Tagged 'cwe-76'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54722: CWE-76: Improper Neutralization of Equivalent Special Elements in HackingRepo dssrf-jsCVE-2026-54722
0

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attacker-controlled URL to bypass internal-IP validation and cause a client using the original URL to reach an internal service. This issue is fixed in version 1.0.4.

Join the discussion
CVE-2026-55723: CWE-76 Improper Neutralization of Equivalent Special Elements in F5 NGINX Ingress ControllerCVE-2026-55723
0

CVE-2026-55723 is an injection vulnerability in the configuration generator of F5 NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. Authenticated users with permission to create or modify these CRDs or annotations can inject arbitrary NGINX configuration directives due to lack of sanitization of user-controllable fields. This vulnerability affects control plane operations only and does not expose the data plane. Versions 5.0.0 and 2026-lts-r1 are affected.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cwe-76
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses