CWE-349— Acceptance of Extraneous Untrusted Data With Trusted Data
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.— MITRE CWE catalog
50 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-349page 1 of 1
- CVE-2026-42960CRITICALCVSS 10.0EG 10.02026-05-20
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cac…
- CVE-2026-41120CRITICALCVSS 9.8EG 9.82026-06-25
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leadi…
- CVE-2023-51655CRITICALCVSS 9.8EG 9.82023-12-21
In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration
- CVE-2019-9535CRITICALCVSS 9.8EG 9.82019-10-09
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including…
- CVE-2026-50252CRITICALCVSS 9.3EG 9.32026-07-22
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port …
- CVE-2026-54047CRITICALCVSS 9.2EG 9.22026-09-11
Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on…
- CVE-2026-45602CRITICALCVSS 9.1EG 9.12026-06-09
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
- CVE-2024-27185CRITICALCVSS 9.1EG 9.12024-08-20
The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.
- CVE-2024-25638HIGHCVSS 8.9EG 8.92024-07-22
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.
- CVE-2026-95985HIGHCVSS 8.8EG 8.82026-09-24
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace,…
- CVE-2018-1131HIGHCVSS 8.8EG 8.82018-05-15
Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache configured to accept cert…
- CVE-2026-48100HIGHCVSS 8.7EG 8.72026-09-28
Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its inner proofs into a public messages: [Field; 1000] array, but it …
- CVE-2025-5994HIGHCVSS 8.7EG 8.72025-07-16
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND …
- CVE-2025-40778HIGHCVSS 8.6EG 8.62025-10-22
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 thro…
- CVE-2025-40776HIGHCVSS 8.6EG 8.62025-07-16
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.…
- CVE-2026-32162HIGHCVSS 8.4EG 8.42026-04-14
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.
- CVE-2021-21374HIGHCVSS 8.1EG 8.12021-03-26
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS without full verification of the SSL/TLS certificate due …
- CVE-2026-35641HIGHCVSS 7.8EG 7.82026-04-10
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious code by crafting a .npmrc file with a git executable override. During npm install…
- CVE-2020-8023HIGHCVSS 7.7EG 7.72020-09-01
A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise …
- CVE-2026-33612HIGHCVSS 7.5EG 7.52026-06-25
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
- CVE-2025-29842HIGHCVSS 7.5EG 7.52025-05-13
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-29816HIGHCVSS 7.5EG 7.52025-04-08
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-27415HIGHCVSS 7.5EG 7.52025-03-19
Nuxt is an open-source web development framework for Vue.js. Prior to 3.16.0, by sending a crafted HTTP request to a server behind an CDN, it is possible in some circumstances to poison the CDN cache and highly impacts the availability of …
- CVE-2024-41924HIGHCVSS 7.2EG 7.22024-07-30
Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative privilege may install an arbitrary PHP package. If the obso…
- CVE-2023-44317HIGHCVSS 7.2EG 7.22023-11-14
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions …
- CVE-2024-53848HIGHCVSS 7.1EG 7.12024-11-29
check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cache, e.g. `https://example.org/schema.json` will be stored as…
- CVE-2023-3749HIGHCVSS 7.1EG 7.12023-08-03
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
- CVE-2025-48804MEDIUMCVSS 6.8EG 6.82025-07-08
Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2026-19033MEDIUMCVSS 6.5EG 6.52026-09-16
For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a…
- CVE-2026-74916MEDIUMCVSS 6.5EG 6.52026-09-01
The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered …
- CVE-2024-42483MEDIUMCVSS 6.5EG 6.52024-09-12
ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not differentiated by message types, it is a single, shared…
- CVE-2024-3367MEDIUMCVSS 6.5EG 6.52024-04-16
Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to inject one argument to runmqsc
- CVE-2024-52555MEDIUMCVSS 6.3EG 6.32024-11-15
In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script
- CVE-2020-10751MEDIUMCVSS 6.1EG 6.12020-05-26
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink mess…
- CVE-2026-1642MEDIUMCVSS 5.9EG 5.92026-02-04
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond…
- CVE-2026-78301MEDIUMCVSS 5.8EG 5.82026-09-16
A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configu…
- CVE-2025-11411MEDIUMCVSS 5.7EG 5.72025-10-22
NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their deleg…
- CVE-2026-46342MEDIUMCVSS 5.4EG 5.42026-05-19
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, the /__nuxt_i…
- CVE-2025-68269MEDIUMCVSS 5.4EG 5.42025-12-16
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
- CVE-2024-34083MEDIUMCVSS 5.4EG 5.42024-05-18
aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted con…
- CVE-2025-11703MEDIUMCVSS 5.3EG 5.32025-10-18
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying o…
- CVE-2023-5548MEDIUMCVSS 5.3EG 5.32023-11-09
Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.
- CVE-2026-54625MEDIUMCVSS 4.8EG 4.82026-08-20
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key functio…
- CVE-2026-15387MEDIUMCVSS 4.3EG 4.32026-08-26
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influen…
- CVE-2025-46339MEDIUMCVSS 4.3EG 4.32025-06-04
FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, it's possible to poison feed favicons by adding a given URL as a feed with the proxy set to an attacker-controlled one and disabled SSL verifying. The favicon hash is …
- CVE-2025-20255MEDIUMCVSS 4.3EG 4.32025-05-21
A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malic…
- CVE-2026-44572LOWCVSS 3.7EG 3.72026-05-13
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redire…
- CVE-2024-21094LOWCVSS 3.7EG 3.72024-04-16
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22, 17.0.10, 2…
- CVE-2026-62364LOWCVSS 2.3EG 2.32026-09-22
wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KE…
- CVE-2025-1680UnratedEG not assessed2025-10-23
An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switches, which allows attackers with administrative privileges to manipulate HTTP Host headers by injecting a specially cr…
Map vulnerabilities like CWE-349 to your infrastructure
EchelonGraph correlates every CVE — across CWE-349 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →