CWE-390

CWE-390 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-390, highest CVSS first.

  1. MEDIUM 5.3CVE-2026-104002public PoC

    A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.  To remediate this issue, users should upgrade to version 3.35.0.

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.7CVE-2026-85716public PoC

    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM ServerSignature or Dig…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-104480public PoC

    Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or wit…

    AI risk analysis on Exploit-DB.ai →