CWE-367— Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.— MITRE CWE catalog
865 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-367page 1 of 18
- CVE-2025-22224CRITICALCVSS 9.3EG 9.3⚠ KEV2025-03-04
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute c…
- CVE-2023-35311CRITICALCVSS 7.5EG 9.0⚠ KEV2023-07-11
Microsoft Outlook Security Feature Bypass Vulnerability
- CVE-2025-38352CRITICALCVSS 7.4EG 9.0⚠ KEV2025-07-22
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls hand…
- CVE-2015-3246CRITICALCVSS 7.4EG 9.0⚠ KEV2015-08-11
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error …
- CVE-2024-30088CRITICALCVSS 7.0EG 9.0⚠ KEV2024-06-11
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2022-48618CRITICALCVSS 7.0EG 9.0⚠ KEV2024-01-09
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. A…
- CVE-2025-64180CRITICALCVSS 10.0EG 10.02025-11-07
Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network resources. The flaw lies in the fundamental design of the DN…
- CVE-2026-68488CRITICALCVSS 9.9EG 9.92026-09-10
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
- CVE-2026-63297CRITICALCVSS 9.9EG 9.92026-08-12
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a targe…
- CVE-2026-25052CRITICALCVSS 9.9EG 9.92026-02-04
n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the…
- CVE-2025-13032CRITICALCVSS 9.9EG 9.92025-11-11
Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3 on windows allows local attacker to escalate privelages via pool overflow.
- CVE-2026-64091CRITICALCVSS 9.8EG 9.82026-07-19
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buf…
- CVE-2026-53838CRITICALCVSS 9.8EG 9.82026-06-12
OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node author…
- CVE-2026-37531CRITICALCVSS 9.8EG 9.82026-05-01
AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP ent…
- CVE-2024-41787CRITICALCVSS 9.8EG 9.82025-01-10
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerabil…
- CVE-2024-56337CRITICALCVSS 9.8EG 9.82024-12-20
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were E…
- CVE-2024-50379CRITICALCVSS 9.8EG 9.82024-12-17
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue …
- CVE-2024-41779CRITICALCVSS 9.8EG 9.82024-11-22
IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vuln…
- CVE-2024-27114CRITICALCVSS 9.8EG 9.82024-09-11
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few millisecon…
- CVE-2024-28718CRITICALCVSS 9.8EG 9.82024-04-12
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.
- CVE-2023-4008CRITICALCVSS 9.8EG 9.82023-08-03
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages wi…
- CVE-2021-32708CRITICALCVSS 9.8EG 9.82021-06-24
Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user to execute code rem…
- CVE-2019-5421CRITICALCVSS 9.8EG 9.82019-04-03
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable` class, more specifically at the `#increment_failed_attempts` method. File location: lib/devise/mod…
- CVE-2019-7249CRITICALCVSS 9.8EG 9.82019-01-31
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.
- CVE-2026-54754CRITICALCVSS 9.6EG 9.62026-08-28
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPerce…
- CVE-2026-44112CRITICALCVSS 9.6EG 9.62026-05-06
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during files…
- CVE-2026-19410CRITICALCVSS 9.4EG 9.42026-08-31
An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppre…
- CVE-2025-58151CRITICALCVSS 9.4EG 9.42026-07-09
varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, there were insufficient compiler barriers…
- CVE-2026-78319CRITICALCVSS 9.3EG 9.32026-09-01
A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result i…
- CVE-2022-33257CRITICALCVSS 9.3EG 9.32023-03-10
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
- CVE-2021-35090CRITICALCVSS 9.3EG 9.32022-06-14
Possible hypervisor memory corruption due to TOC TOU race condition when updating address mappings in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2026-24071CRITICALCVSS 7.8EG 9.32026-02-02
It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection…
- CVE-2026-82761CRITICALCVSS 9.1EG 9.12026-09-17
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configured…
- CVE-2026-44694CRITICALCVSS 9.1EG 9.12026-05-08
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before version 2.50.2, there is an authenticated server-side request forgery vulnerability affecting …
- CVE-2024-49768CRITICALCVSS 9.1EG 9.12024-10-29
Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondary request using HTTP pipelining. When request lookahead is d…
- CVE-2021-35082CRITICALCVSS 9.1EG 9.12022-06-14
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT
- CVE-2021-30347CRITICALCVSS 9.1EG 9.12022-06-14
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon…
- CVE-2021-30343CRITICALCVSS 9.1EG 9.12022-06-14
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2021-30342CRITICALCVSS 9.1EG 9.12022-06-14
Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice…
- CVE-2022-28743CRITICALCVSS 9.1EG 9.12022-04-21
Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, and Application FW <= 2.91.2.66, allows an authenticated remote attacker with administrator permissions to execute arbitr…
- CVE-2026-77972CRITICALCVSS 9.0EG 9.02026-09-15
Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the address…
- CVE-2026-20677CRITICALCVSS 9.0EG 9.02026-02-11
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut …
- CVE-2026-25641CRITICALCVSS 9.0EG 9.02026-02-06
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performed and the key used for accessing properties. Even though the key us…
- CVE-2025-34027CRITICALCVSS 9.0EG 9.02025-05-21
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for …
- CVE-2024-0132CRITICALCVSS 9.0EG 9.02024-09-26
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not…
- CVE-2023-32156CRITICALCVSS 8.8EG 9.02024-05-03
Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to execu…
- CVE-2022-36980CRITICALCVSS 8.1EG 9.02023-03-29
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be b…
- CVE-2026-71539HIGHCVSS 8.9EG 8.92026-08-18
n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted re…
- CVE-2026-47746HIGHCVSS 8.9EG 8.92026-08-03
Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing con…
- CVE-2026-106207HIGHCVSS 8.8EG 8.82026-10-06
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Map vulnerabilities like CWE-367 to your infrastructure
EchelonGraph correlates every CVE — across CWE-367 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →