CWE-204

CWE-204 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-204, highest CVSS first.

  1. HIGH 7.4CVE-2026-60007public PoC

    In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted usernam

    milo

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.3CVE-2026-55998public PoC

    The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_regist

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-14202

    Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

    AI risk analysis on Exploit-DB.ai →