The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
Volume of CVEs assigned to CWE-1286 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
88 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7954CRITICAL The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can exe | Aug 23, 2024 | 9.8 | 89 | NO | YES |
CVE-2026-42579CRITICAL Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints d | May 13, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-25679HIGH url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. | Mar 6, 2026 | 7.5 | 36 | NO | NO |
CVE-2025-13878HIGH Malformed BRID/HHIT records can cause `named` to terminate unexpectedly.
This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.1 | Jan 21, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-57026HIGH An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticate | Jul 9, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-50131HIGH Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding | Jun 10, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-48059HIGH Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in n | Jun 12, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-6918HIGH In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. | May 5, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-33218HIGH NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode por | Mar 25, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-27889HIGH NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity | Mar 25, 2026 | 7.5 | 33 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.