CWE-204
CWE-204 · 3 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-204, highest CVSS first.
- HIGH 7.4CVE-2026-60007public PoC
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted usernam…
milo
- MEDIUM 5.3CVE-2026-55998public PoC
The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_regist…
- MEDIUM 5.3CVE-2026-14202
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.