CWE-130— Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.— MITRE CWE catalog
123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-130page 2 of 3
- CVE-2024-53856HIGHCVSS 7.5EG 7.52024-12-05
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.
- CVE-2024-41991HIGHCVSS 7.5EG 7.52024-08-07
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very l…
- CVE-2024-41990HIGHCVSS 7.5EG 7.52024-08-07
An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
- CVE-2024-39614HIGHCVSS 7.5EG 7.52024-07-10
An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.
- CVE-2024-38875HIGHCVSS 7.5EG 7.52024-07-10
An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets.
- CVE-2023-33192HIGHCVSS 7.5EG 7.52023-05-27
ntpd-rs is an NTP implementation written in Rust. ntpd-rs does not validate the length of NTS cookies in received NTP packets to the server. An attacker can crash the server by sending a specially crafted NTP packet containing a cookie sho…
- CVE-2023-28964HIGHCVSS 7.5EG 7.52023-04-17
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network based, unauthenticated attacker to cause an RPD crash leading to a…
- CVE-2022-41586HIGHCVSS 7.5EG 7.52022-10-14
The communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2022-3290HIGHCVSS 7.5EG 7.52022-09-26
Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- CVE-2022-3272HIGHCVSS 7.5EG 7.52022-09-26
Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- CVE-2022-0677HIGHCVSS 7.5EG 7.52022-04-07
Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. T…
- CVE-2021-43666HIGHCVSS 7.5EG 7.52022-03-24
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
- CVE-2022-0618HIGHCVSS 7.5EG 7.52022-03-10
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS or HTTP/2 PUSH_PR…
- CVE-2022-24666HIGHCVSS 7.5EG 7.52022-02-09
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is ca…
- CVE-2021-20610HIGHCVSS 7.5EG 7.52021-12-01
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PC…
- CVE-2021-36090HIGHCVSS 7.5EG 7.52021-07-13
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against …
- CVE-2021-35517HIGHCVSS 7.5EG 7.52021-07-13
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against …
- CVE-2021-35516HIGHCVSS 7.5EG 7.52021-07-13
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against s…
- CVE-2019-0055HIGHCVSS 7.5EG 7.52019-10-09
A vulnerability in the SIP ALG packet processing service of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending specific types of valid SIP traffic to the device. In this case, the flowd…
- CVE-2018-5453HIGHCVSS 7.5EG 7.52018-03-05
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become…
- CVE-2026-4371HIGHCVSS 7.4EG 7.42026-03-24
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfu…
- CVE-2023-5393HIGHCVSS 7.4EG 7.42024-04-11
Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends updating to the most recent version of the product. See Honeywell Se…
- CVE-2024-35313HIGHCVSS 7.3EG 7.32024-05-17
In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.
- CVE-2025-8531MEDIUMCVSS 6.8EG 6.82025-09-19
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the first 5…
- CVE-2026-67292MEDIUMCVSS 6.5EG 6.52026-08-01
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to …
- CVE-2026-48685MEDIUMCVSS 6.5EG 6.52026-05-26
FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_bgp_attribute() function correctly ident…
- CVE-2026-5265MEDIUMCVSS 6.5EG 6.52026-04-24
When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IP…
- CVE-2026-40199MEDIUMCVSS 6.5EG 6.52026-04-10
Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped addresses…
- CVE-2026-34831MEDIUMCVSS 6.5EG 6.52026-04-02
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Content-Length response header using String#size instead of String#bytesize. When the response body contains multibyte UTF-…
- CVE-2025-48022MEDIUMCVSS 6.5EG 6.52026-02-13
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and ve…
- CVE-2025-52949MEDIUMCVSS 6.5EG 6.52025-07-11
An Improper Handling of Length Parameter Inconsistency vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a logically adjacent BGP peer sending a specifically malformed BGP packet to…
- CVE-2024-20416MEDIUMCVSS 6.5EG 6.52024-07-17
A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient boundary…
- CVE-2023-50248MEDIUMCVSS 6.5EG 6.52023-12-13
CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the `/dataset/new` endpoint (including either the a…
- CVE-2020-16224MEDIUMCVSS 6.5EG 6.52020-09-11
In Patient Information Center iX (PICiX) Versions C.02, C.03, the software parses a formatted message or structure but does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated d…
- CVE-2026-60060MEDIUMCVSS 6.3EG 6.32026-07-17
Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of…
- CVE-2024-29064MEDIUMCVSS 6.2EG 6.22024-04-09
Windows Hyper-V Denial of Service Vulnerability
- CVE-2026-45681MEDIUMCVSS 5.9EG 5.92026-05-18
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, w…
- CVE-2024-20685MEDIUMCVSS 5.9EG 5.92024-04-09
Azure Private 5G Core Denial of Service Vulnerability
- CVE-2026-33555MEDIUMCVSS 5.8EG 5.82026-04-13
An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches a previously announced content-length when the stream is closed via a frame with an empty payload. This can cause desyn…
- CVE-2026-62424MEDIUMCVSS 5.5EG 5.52026-07-28
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from…
- CVE-2026-62423MEDIUMCVSS 5.5EG 5.52026-07-28
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver derives several lengths directly from…
- CVE-2026-25572MEDIUMCVSS 5.5EG 5.52026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized …
- CVE-2026-25571MEDIUMCVSS 5.5EG 5.52026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized …
- CVE-2025-26432MEDIUMCVSS 5.5EG 5.52025-09-04
In multiple locations, there is a possible way to persistently DoS the device due to a missing length check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2021-26329MEDIUMCVSS 5.5EG 5.52021-11-16
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.
- CVE-2021-36374MEDIUMCVSS 5.5EG 5.52021-07-14
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using A…
- CVE-2021-36373MEDIUMCVSS 5.5EG 5.52021-07-14
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apac…
- CVE-2026-71402MEDIUMCVSS 5.4EG 5.42026-08-27
An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length instead of the length of the remaining UDP payload. Consequentl…
- CVE-2026-6432MEDIUMCVSS 5.3EG 5.32026-06-25
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
- CVE-2026-48487MEDIUMCVSS 5.3EG 5.32026-06-22
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checki…
Map vulnerabilities like CWE-130 to your infrastructure
EchelonGraph correlates every CVE — across CWE-130 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →