Threats Tagged 'cwe-841'
View all threats tagged with 'cwe-841'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-841'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-57536: CWE-841 Improper enforcement of behavioral workflow in pretix pretix-mollieCVE-2026-57536 0 Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. Join the discussion | CVE Database V5 | 06/25/2026, 14:08:37 UTC Added: 06/25/2026, 14:46:09 UTC |
CVE-2026-13223: CWE-841 Improper enforcement of behavioral workflow in pretix pretix-computopCVE-2026-13223 0 Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. Join the discussion | CVE Database V5 | 06/25/2026, 14:03:54 UTC Added: 06/25/2026, 14:46:08 UTC |
CVE-2026-13222: CWE-841 Improper enforcement of behavioral workflow in pretix pretix-oppwaCVE-2026-13222 0 Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. Join the discussion | CVE Database V5 | 06/25/2026, 14:07:03 UTC Added: 06/25/2026, 14:46:08 UTC |
CVE-2026-48505: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in filamentphp filamentCVE-2026-48505 0 Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. If an attacker gains access to both the user's password and their recovery codes, they get two authenticated sessions per recovery code burned instead of one, or more if they batch the parallel submissions wider, materially extending the attacker's window of access compared to what the single-use guarantee implies. This vulnerability is fixed in 4.11.5 and 5.6.5. Join the discussion | CVE Database V5 | 06/22/2026, 21:39:26 UTC Added: 06/22/2026, 22:09:29 UTC |
CVE-2026-46540: CWE-841: Improper Enforcement of Behavioral Workflow in nimiq core-rs-albatrossCVE-2026-46540 0 Nimiq core-rs-albatross versions prior to 1.4.0 contain a vulnerability where the LightBlockchain::rebranch() function improperly updates blockchain state when adopting a fork chain ending in a macro block. This leads to stale macro block and validator state, causing verification failures and stalling the light client's chain progression. The issue is fixed in version 1.4.0. Join the discussion | CVE Database V5 | 06/09/2026, 23:45:01 UTC Added: 06/09/2026, 23:55:53 UTC |
CVE-2026-43974: CWE-841 Improper Enforcement of Behavioral Workflow in ninenines gunCVE-2026-43974 0 Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicited 101 Switching Protocols response. In gun_http:handle_inform/8, when a 101 Switching Protocols response is received over HTTP/1.1, the function verifies only that the Upgrade header is syntactically valid and that the stream reference is a plain reference(). It does not check whether the client ever sent an Upgrade or Connection: upgrade header on the corresponding request. Because this check is absent, any 101 response (solicited or not) causes gun to dispatch a gun_upgrade message to the caller and transition the entire connection to raw protocol mode. A malicious or compromised HTTP server can send an unsolicited 101 response to any HTTP/1.1 request, causing the gun client to abandon HTTP framing for that connection. Once in raw mode, gun_raw applies no flow control (flow=infinity) and re-arms socket active mode after every received packet, so the server can flood the client with arbitrary bytes. These are forwarded as unbounded gun_data messages to the owner process, exhausting its mailbox and BEAM memory, ultimately crashing the VM. This issue affects gun: from 2.0.0 before 2.4.0. Join the discussion | CVE Database V5 | 06/08/2026, 14:12:36 UTC Added: 06/08/2026, 14:33:53 UTC |
CVE-2024-13065: CWE-841 Improper Enforcement of Behavioral Workflow in Akinsoft MyRezztaCVE-2024-13065 0 Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows Input Data Manipulation, CAPEC - 125 - Flooding. This issue affects MyRezzta: from s2.02.02 before v2.05.01. Join the discussion | CVE Database V5 | 09/03/2025, 08:48:48 UTC Added: 06/01/2026, 13:03:46 UTC |
CVE-2026-45023: CWE-770: Allocation of Resources Without Limits or Throttling in Significant-Gravitas AutoGPTCVE-2026-45023 0 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes blocks without consuming any credits, regardless of the user's balance. The credit check that exists in the graph execution path (manager.py) is never reached when blocks are called directly via the external API, allowing unlimited free execution of all blocks. This vulnerability is fixed in 0.6.59. Join the discussion | CVE Database V5 | 05/28/2026, 21:30:55 UTC Added: 05/28/2026, 22:18:34 UTC |
Showing 1 to 8 of 8 results