CWE-471
CWE-471 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-471, highest CVSS first.
- MEDIUM 6.5CVE-2026-103001public PoC
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for …
- MEDIUM 4CVE-2026-92949public PoC
vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSett…
- LOW 3.7CVE-2026-107296public PoC
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse enc…