CWE-130
CWE-130 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-130, highest CVSS first.
- HIGH 7.5CVE-2026-87022
Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.…
- HIGH 7.5CVE-2026-73455
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
- UNSCOREDCVE-2026-77619public PoC
Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenticated remote peer that …