CWE-134— Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.— MITRE CWE catalog
400 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-134page 8 of 8
- CVE-2025-22482HIGHCVSS 8.1EG 8.12025-06-06
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have…
- CVE-2025-24359HIGHCVSS 8.4EG 8.42025-01-24
ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the context of…
- CVE-2025-30269HIGHCVSS 8.1EG 8.12026-02-11
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have alrea…
- CVE-2025-36202HIGHCVSS 7.5EG 7.52025-09-22
IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external sou…
- CVE-2025-40600CRITICALCVSS 9.8EG 9.82025-07-29
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
- CVE-2025-46121CRITICALCVSS 9.8EG 9.82025-07-21
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the for…
- CVE-2025-46123HIGHCVSS 7.2EG 7.22025-07-21
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest p…
- CVE-2025-48388MEDIUMCVSS 6.5EG 6.52025-05-29
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an atta…
- CVE-2025-48730MEDIUMCVSS 6.5EG 6.52025-10-03
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret da…
- CVE-2025-48826HIGHCVSS 8.8EG 8.82025-10-07
A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to memory corruption. An attacker can send a series of HTTP requests to trigger th…
- CVE-2025-52429MEDIUMCVSS 6.5EG 6.52025-10-03
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret da…
- CVE-2025-52666LOWCVSS 2.7EG 2.72025-11-20
Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.
- CVE-2025-53406MEDIUMCVSS 6.5EG 6.52025-10-03
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret da…
- CVE-2025-53407MEDIUMCVSS 6.5EG 6.52025-10-03
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret da…
- CVE-2025-53591MEDIUMCVSS 6.5EG 6.52026-01-02
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to obtain secret da…
- CVE-2025-55298HIGHCVSS 7.5EG 7.52025-08-26
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user inpu…
- CVE-2025-64157HIGHCVSS 7.2EG 7.22026-02-10
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized c…
- CVE-2025-68648HIGHCVSS 7.2EG 7.22026-03-10
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAn…
- CVE-2025-68949MEDIUMCVSS 5.3EG 5.32026-01-13
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accep…
- CVE-2026-0400MEDIUMCVSS 4.9EG 4.92026-02-24
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
- CVE-2026-10828MEDIUMCVSS 6.9EG 6.92026-06-16
A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and imp…
- CVE-2026-12004HIGHCVSS 8.7EG 8.72026-08-12
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface t…
- CVE-2026-12174HIGHCVSS 8.8EG 8.82026-06-13
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format stri…
- CVE-2026-15680HIGHCVSS 7.5EG 7.52026-07-13
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lorex 2K Indoor Wi-Fi Secu…
- CVE-2026-15809HIGHCVSS 7.8EG 7.82026-07-15
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME env…
- CVE-2026-15961MEDIUMCVSS 6.0EG 6.02026-08-19
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings.
- CVE-2026-17136CRITICALCVSS 9.8EG 9.82026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
- CVE-2026-18186HIGHCVSS 8.1EG 8.12026-07-30
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written into a task log and later processed through an unsafe format string oper…
- CVE-2026-18187HIGHCVSS 8.1EG 8.12026-07-30
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an error response and processed through an unsafe format string operation. An authent…
- CVE-2026-18188HIGHCVSS 8.1EG 8.12026-07-30
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may be processed through an unsafe format string operation. An authenticated at…
- CVE-2026-21640LOWCVSS 2.7EG 2.72026-01-20
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fata…
- CVE-2026-22190HIGHCVSS 7.5EG 7.52026-01-07
The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a single…
- CVE-2026-3008MEDIUMCVSS 6.6EG 6.62026-04-27
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.
- CVE-2026-33210CRITICALCVSS 9.1EG 9.12026-03-20
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_dup…
- CVE-2026-3509HIGHCVSS 7.5EG 7.52026-03-24
An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.
- CVE-2026-44407MEDIUMCVSS 4.7EG 4.72026-05-07
A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.
- CVE-2026-46465MEDIUMCVSS 5.5EG 5.52026-07-03
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of external…
- CVE-2026-50211CRITICALCVSS 9.8EG 9.82026-06-04
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
- CVE-2026-57877HIGHCVSS 8.6EG 8.62026-06-26
An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the l…
- CVE-2026-6241MEDIUMCVSS 6.8EG 6.82026-06-05
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifi…
- CVE-2026-6242MEDIUMCVSS 6.8EG 6.82026-06-05
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting functions. An attacker may inject crafted format strings into…
- CVE-2026-6250HIGHCVSS 8.1EG 8.12026-06-11
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate sta…
- CVE-2026-63073UnratedEG not assessed2026-08-25
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client tha…
- CVE-2026-6390MEDIUMCVSS 6.8EG 6.82026-07-23
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. T…
- CVE-2026-6474MEDIUMCVSS 4.3EG 4.32026-05-14
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
- CVE-2026-6539MEDIUMCVSS 4.4EG 4.42026-04-30
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attac…
- CVE-2026-67244HIGHCVSS 7.2EG 7.22026-07-30
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticat…
- CVE-2026-6843MEDIUMCVSS 5.5EG 5.52026-04-22
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading t…
- CVE-2026-68553HIGHCVSS 7.1EG 7.12026-08-19
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation a…
- CVE-2026-7835LOWCVSS 3.1EG 3.12026-05-21
A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.
Map vulnerabilities like CWE-134 to your infrastructure
EchelonGraph correlates every CVE — across CWE-134 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →