The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
Volume of CVEs assigned to CWE-1289 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48710MEDIUM Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because | May 26, 2026 | 6.5 | 51 | NO | YES |
CVE-2026-39821CRITICAL The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns th | May 22, 2026 | 9.6 | 46 | NO | NO |
CVE-2026-47729MEDIUM Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnera | Jul 16, 2026 | 6.5 | 42 | NO | NO |
CVE-2025-62718CRITICAL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. R | Apr 9, 2026 | 9.9 | 41 | NO | NO |
CVE-2026-33729CRITICAL OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditi | Mar 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-33810HIGH When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constra | Apr 8, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-42462HIGH Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of | Jun 10, 2026 | 7.0 | 31 | NO | NO |
CVE-2026-49942HIGH Net::CIDR::Set versions through 0.20 for Perl did not validate network masks.
The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661) | Jun 4, 2026 | 7.3 | 31 | NO | NO |
CVE-2026-35039CRITICAL fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for di | Apr 6, 2026 | 9.1 | 31 | NO | NO |
CVE-2026-50090MEDIUM The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of | Jun 12, 2026 | 6.1 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.