CWE-187— Partial String Comparison
The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.— MITRE CWE catalog
18 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-187page 1 of 1
- CVE-2024-41110CRITICALCVSS 9.9EG 9.92024-07-24
Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under sp…
- CVE-2022-31802CRITICALCVSS 9.8EG 9.82022-06-24
In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared to the real CODESYS Gateway password. An attacker may perform authentication by specifying a small password that matche…
- CVE-2026-35031HIGHCVSS 8.8EG 8.82026-04-14
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversa…
- CVE-2026-55602HIGHCVSS 8.6EG 8.62026-06-18
http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses una…
- CVE-2024-39742HIGHCVSS 8.1EG 8.12024-07-08
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
- CVE-2026-30874HIGHCVSS 7.8EG 7.82026-03-19
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject an arbitrary PATH var…
- CVE-2026-87853HIGHCVSS 7.5EG 7.52026-09-09
A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an…
- CVE-2026-44837HIGHCVSS 7.5EG 7.52026-05-26
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whe…
- CVE-2026-34785HIGHCVSS 7.5EG 7.52026-04-02
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes suc…
- CVE-2026-101914MEDIUMCVSS 6.5EG 6.52026-09-28
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher used by RBAC performs a prefix comparison instead of an equality comparison…
- CVE-2026-62750MEDIUMCVSS 6.5EG 6.52026-08-11
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.
- CVE-2026-84376MEDIUMCVSS 6.3EG 6.32026-09-02
Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a request …
- CVE-2026-94576MEDIUMCVSS 5.9EG 5.92026-10-08
An authentication logic and privilege escalation vulnerability exists in the account management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Under specific conditions, an authenticated user can bypass …
- CVE-2024-39743MEDIUMCVSS 5.9EG 5.92024-07-08
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation. A remote attacker could exploit this vulnerability to cause the server to co…
- CVE-2026-81479MEDIUMCVSS 5.5EG 5.82026-09-17
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.
- CVE-2026-14687MEDIUMCVSS 5.3EG 5.32026-07-05
A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine search-result Deduplication. Executing a manipulation can lead …
- CVE-2026-45692LOWCVSS 3.8EG 3.82026-05-19
Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one confi…
- CVE-2025-23384LOWCVSS 3.7EG 3.72025-03-11
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions …
Map vulnerabilities like CWE-187 to your infrastructure
EchelonGraph correlates every CVE — across CWE-187 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →