CWE-390
CWE-390 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-390, highest CVSS first.
- MEDIUM 5.3CVE-2026-104002public PoC
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0.
- LOW 3.7CVE-2026-85716public PoC
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Dig…
- UNSCOREDCVE-2026-104480public PoC
Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or wit…