CWE-1023
CWE-1023 · 4 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-1023, highest CVSS first.
- HIGH 8.8CVE-2026-85491
Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal replaces the dispatcher's prepare_action with a version that …
- HIGH 7.5CVE-2026-24255public PoC
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vuln…
dynamo · linux kernel
- MEDIUM 6.5CVE-2026-91768public PoC
The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing the first 96 bits with …
- UNSCOREDCVE-2026-92611public PoC
In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and a…