The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.
Volume of CVEs assigned to CWE-170 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
52 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42010CRITICAL A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated username | May 7, 2026 | 9.8 | 42 | NO | NO |
CVE-2021-22931CRITICAL Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name S | Aug 16, 2021 | 9.8 | 42 | NO | NO |
CVE-2026-5067CRITICAL A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Key header. The HTTP/1 header par | Jun 9, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-8721CRITICAL Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs.
Password parameters in PKCS12.xs are declared char *, which routes through Perl's de | May 17, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-34464HIGH Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_ | May 5, 2026 | 8.8 | 32 | NO | NO |
CVE-2025-2026HIGH The NPort 6100-G2/6200-G2 Series is affected by a high-severity vulnerability (CVE-2025-2026) that allows remote attackers to execute a null byte injection through the device’s web | Dec 31, 2025 | 7.1 | 32 | NO | NO |
CVE-2026-55738HIGH A stack-based buffer overflow exists in the raw_to_header() function in src/microtar.c in rxi microtar 0.1.0. The function copies the 100-byte name and linkname fields of a TAR hea | Jun 17, 2026 | 8.8 | 31 | NO | NO |
CVE-2021-31886CRITICAL A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC | Nov 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-34462HIGH Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, an | May 5, 2026 | 7.8 | 30 | NO | NO |
CVE-2025-67733HIGH Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the | Feb 23, 2026 | 7.1 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.