CWE-129

CWE-129 · 10 records · 9 with a public proof-of-concept

Records the NVD classes under CWE-129, highest CVSS first.

  1. HIGH 7.5CVE-2026-61695public PoC

    Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unk…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-100654public PoC

    vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that the values are integers, not that each token id is within the model vocabulary/logits range.…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.2CVE-2026-62866public PoC

    Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the source at the exhausted …

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.1CVE-2026-17413

    IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface. An attacker with administrator-level (root) access …

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 4.3CVE-2026-100836public PoC

    Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trig…

    AI risk analysis on Exploit-DB.ai →

  6. LOW 3.3CVE-2026-96675public PoC

    alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-b…

    AI risk analysis on Exploit-DB.ai →

  7. LOW 3.1CVE-2026-93989public PoC

    vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of concurrent requests, ca…

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-65653public PoC

    github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first element. A network peer can…

    AI risk analysis on Exploit-DB.ai →

  9. UNSCOREDCVE-2026-65652public PoC

    github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with an unsupported checksu…

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-16651public PoC

    temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned by strings.IndexFunc bef…

    AI risk analysis on Exploit-DB.ai →