CWE-471

CWE-471 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-471, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-103001public PoC

    PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for …

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 4CVE-2026-92949public PoC

    vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescriptor() or __lookupSett…

    AI risk analysis on Exploit-DB.ai →

  3. LOW 3.7CVE-2026-107296public PoC

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse enc…

    AI risk analysis on Exploit-DB.ai →