CWE-248

CWE-248 · 15 records · 13 with a public proof-of-concept

Records the NVD classes under CWE-248, highest CVSS first.

  1. HIGH 8.6CVE-2026-92954public PoC

    vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created inside the sandbox are wra…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-102281public PoC

    Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-92608

    Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issu…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-95842public PoC

    Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command that raises an uncaught exception can terminate an event loop sha…

    moquette

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-62985public PoC

    request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal privat…

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-94622public PoC

    vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncau…

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-88411public PoC

    Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 6.8CVE-2026-100722public PoC

    vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHandler, the apply trap calls markHostPromiseHandled() on the returned value, but the adjacent construct path returns the result of Reflect.cons…

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 6.5CVE-2026-100675public PoC

    stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes mass mention messages. Authenticated users can send five crafted role-mention messages to terminate all acknowledgement workers, disabling p…

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 5.9CVE-2026-92081public PoC

    fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, which is forbi…

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 5.3CVE-2026-101918public PoC

    PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursivel…

    AI risk analysis on Exploit-DB.ai →

  12. MEDIUM 5.3CVE-2026-101035public PoC

    A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipulation can lead to uncaught exception. The attack can be launched remotely. …

    AI risk analysis on Exploit-DB.ai →

  13. MEDIUM 5.3CVE-2026-92905

    ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.

    AI risk analysis on Exploit-DB.ai →

  14. MEDIUM 4.3CVE-2026-101101public PoC

    A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. The manipulation leads to uncaught exception. Remote exploitation of the attack is po…

    AI risk analysis on Exploit-DB.ai →

  15. UNSCOREDCVE-2026-82410public PoC

    Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal goroutines can escape rec…

    AI risk analysis on Exploit-DB.ai →