CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 4 of 55
- CVE-2026-106426HIGHCVSS 8.3EG 8.32026-10-06
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-106377HIGHCVSS 8.3EG 8.32026-10-06
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-78934HIGHCVSS 8.3EG 8.32026-08-25
Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-15119HIGHCVSS 8.3EG 8.32026-07-08
Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-12468HIGHCVSS 8.3EG 8.32026-06-17
Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-12454HIGHCVSS 8.3EG 8.32026-06-17
Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-12022HIGHCVSS 8.3EG 8.32026-06-11
Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
- CVE-2026-11677HIGHCVSS 8.3EG 8.32026-06-08
Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-10940HIGHCVSS 8.3EG 8.32026-06-04
Race in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-8520HIGHCVSS 8.3EG 8.32026-05-14
Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-6921HIGHCVSS 8.3EG 8.32026-04-23
Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
- CVE-2022-33636HIGHCVSS 8.3EG 8.32022-08-09
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2022-30128HIGHCVSS 8.3EG 8.32022-06-01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-30127HIGHCVSS 8.3EG 8.32022-06-01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2020-1667HIGHCVSS 8.3EG 8.32020-10-16
When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process might be bypas…
- CVE-2020-1660HIGHCVSS 8.3EG 8.32020-10-16
When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible f…
- CVE-2020-6575HIGHCVSS 8.3EG 8.32020-09-21
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2020-1645HIGHCVSS 8.3EG 8.32020-07-17
When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible f…
- CVE-2019-9818HIGHCVSS 8.3EG 8.32019-07-23
A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note:…
- CVE-2006-5051HIGHCVSS 8.1EG 8.32006-09-27
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
- CVE-2022-41035HIGHCVSS 5.3EG 8.32022-10-11
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- CVE-2026-59324HIGHCVSS 8.2EG 8.22026-08-27
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, corre…
- CVE-2026-64435HIGHCVSS 8.2EG 8.22026-07-25
In the Linux kernel, the following vulnerability has been resolved: audit: Fix data races of skb_queue_len() readers on audit_queue Multiple readers access audit_queue.qlen via skb_queue_len() without holding the queue lock or using READ…
- CVE-2026-43981HIGHCVSS 8.2EG 8.22026-05-26
Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not…
- CVE-2026-41458HIGHCVSS 8.2EG 8.22026-04-22
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attac…
- CVE-2024-47534HIGHCVSS 8.2EG 8.22024-10-01
go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", then the client should trace the delegatio…
- CVE-2021-23892HIGHCVSS 8.2EG 8.22021-05-12
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain …
- CVE-2020-7457HIGHCVSS 8.1EG 8.22020-07-09
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race c…
- CVE-2026-104970HIGHCVSS 8.1EG 8.12026-10-05
Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs acco…
- CVE-2026-79625HIGHCVSS 8.1EG 8.12026-09-30
Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, or to corruption of internal memory structures. An authenti…
- CVE-2026-77762HIGHCVSS 8.1EG 8.12026-09-23
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects Apache Tomcat: from 1…
- CVE-2026-61628HIGHCVSS 8.1EG 8.12026-09-21
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the ha…
- CVE-2026-65415HIGHCVSS 8.1EG 8.12026-09-14
A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kernel …
- CVE-2026-87467HIGHCVSS 8.1EG 8.12026-09-09
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
- CVE-2026-69827HIGHCVSS 8.1EG 8.12026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-69782HIGHCVSS 8.1EG 8.12026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-19506HIGHCVSS 8.1EG 8.12026-08-19
Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.
- CVE-2026-66802HIGHCVSS 8.1EG 8.12026-08-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
- CVE-2026-62778HIGHCVSS 8.1EG 8.12026-08-11
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-61352HIGHCVSS 8.1EG 8.12026-08-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-62820HIGHCVSS 8.1EG 8.12026-08-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
- CVE-2026-43631HIGHCVSS 8.1EG 8.12026-08-06
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary c…
- CVE-2026-63756HIGHCVSS 8.1EG 8.12026-07-20
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent request…
- CVE-2026-56649HIGHCVSS 8.1EG 8.12026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.
- CVE-2026-50460HIGHCVSS 8.1EG 8.12026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50348HIGHCVSS 8.1EG 8.12026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50452HIGHCVSS 8.1EG 8.12026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-42900HIGHCVSS 8.1EG 8.12026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-56297HIGHCVSS 8.1EG 8.12026-07-08
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYN…
- CVE-2026-53518HIGHCVSS 8.1EG 8.12026-07-07
Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code throug…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →