openshift/ose-rhel-coreos-8

Direct Vulnerabilities

Known vulnerabilities in the openshift/ose-rhel-coreos-8 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Use After Free

*
  • H
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • M
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Comparison Using Wrong Factors

*
  • H
Out-of-bounds Write

*
  • L
Trust Boundary Violation

*
  • H
Use After Free

*
  • L
Buffer Access with Incorrect Length Value

*
  • M
Out-of-bounds Write

*
  • M
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Reachable Assertion

*
  • M
Authentication Bypass

*
  • L
Out-of-bounds Write

*
  • H
Heap-based Buffer Overflow

*
  • H
Out-of-bounds Write

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Improper Update of Reference Count

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • H
Reachable Assertion

*
  • H
Integer Overflow or Wraparound

*
  • M
Origin Validation Error

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Resource Exhaustion

*
  • H
Improper Handling of Unicode Encoding

*
  • M
Out-of-bounds Write

*
  • L
Improper Update of Reference Count

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • H
Missing Release of Resource after Effective Lifetime

*
  • L
Expired Pointer Dereference

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Validation of Specified Quantity in Input

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Expired Pointer Dereference

*
  • M
Improper Verification of Cryptographic Signature

*
  • L
Use After Free

*
  • H
Out-of-bounds Read

*
  • M
Integer Underflow

*
  • L
NULL Pointer Dereference

*
  • L
Information Exposure

*
  • M
Incorrect Synchronization

*
  • M
Deadlock

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Improper Update of Reference Count

*
  • M
Race Condition

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Incorrect Bitwise Shift of Integer

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Link Following

*
  • M
Link Following

*
  • L
Use of Uninitialized Resource

*
  • M
NULL Pointer Dereference

*
  • M
Off-by-one Error

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Improper Validation of Specified Quantity in Input

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • M
Incorrect Synchronization

*
  • L
Improper Update of Reference Count

*
  • L
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Improper Resource Locking

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • L
Excessive Platform Resource Consumption within a Loop

*
  • M
Out-of-bounds Read

*
  • L
Access of Uninitialized Pointer

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
NULL Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Access of Uninitialized Pointer

*
  • M
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Race Condition

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
NULL Pointer Dereference

*
  • H
Algorithmic Complexity

*
  • L
Incorrect Synchronization

*
  • L
Out-of-bounds Read

*
  • M
Improper Update of Reference Count

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Information Exposure

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
NULL Pointer Dereference

*
  • M
Deadlock

*
  • M
CVE-2026-89582

*
  • L
Improper Update of Reference Count

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Null Termination

*
  • M
NULL Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Release of Invalid Pointer or Reference

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • M
Path Equivalence

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Reachable Assertion

*
  • M
Missing Lock Check

*
  • M
NULL Pointer Dereference

*
  • M
Release of Invalid Pointer or Reference

*
  • M
Expired Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • L
Improper Update of Reference Count

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Race Condition

*
  • M
Plaintext Storage of a Password

*
  • L
Improper Update of Reference Count

*
  • M
Directory Traversal

*
  • M
Out-of-bounds Read

*
  • L
Improper Validation of Integrity Check Value

*
  • H
Integer Overflow or Wraparound

*
  • H
Incomplete Cleanup

*
  • M
Buffer Overflow

*
  • M
Buffer Overflow

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Integer Underflow

*
  • M
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • H
Improper Update of Reference Count

*
  • M
Expired Pointer Dereference

*
  • M
Divide By Zero

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Improperly Implemented Security Check for Standard

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Misinterpretation of Input

*
  • M
Improper Update of Reference Count

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • L
Incorrect Synchronization

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Consistency within Input

*
  • M
Race Condition

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • H
CVE-2026-89563

*
  • M
Race Condition

*
  • H
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • L
Out-of-bounds Write

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • M
Race Condition

*
  • M
Use of Uninitialized Resource

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Integer Overflow or Wraparound

*
  • M
Incorrect Synchronization

*
  • M
NULL Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • M
Expired Pointer Dereference

*
  • M
Improper Update of Reference Count

*
  • M
Comparison Using Wrong Factors

*
  • M
Incorrect Privilege Assignment

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Buffer Access with Incorrect Length Value

*
  • H
Out-of-bounds Write

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Write

*
  • M
Use of Uninitialized Resource

*
  • M
Buffer Overflow

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Synchronization

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Improper Resource Locking

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Update of Reference Count

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • H
Improper Preservation of Permissions

*
  • M
Out-of-bounds Read

*
  • M
Information Exposure Through Caching

*
  • M
Out-of-bounds Read

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-bounds Write

*
  • M
Integer Underflow

*
  • M
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Access of Uninitialized Pointer

*
  • M
Improper Update of Reference Count

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Expired Pointer Dereference

*
  • M
Access of Uninitialized Pointer

*
  • L
Missing Initialization of Resource

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Write

*
  • M
CVE-2026-89741

*
  • M
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Use of Out-of-range Pointer Offset

*
  • H
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • L
Out-of-bounds Write

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Write

*
  • M
Buffer Overflow

*
  • M
Use of Incorrect Operator

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • H
Expired Pointer Dereference

*
  • L
Improper Handling of Length Parameter Inconsistency

*
  • H
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Race Condition

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Unchecked Input for Loop Condition

*
  • M
Race Condition

*
  • M
NULL Pointer Dereference

*
  • M
Missing Synchronization

*
  • M
Out-of-bounds Read

*
  • M
Missing Initialization of Resource

*
  • M
Out-of-bounds Write

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Information Exposure

*
  • M
CVE-2026-80989

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Expired Pointer Dereference

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Out-of-bounds Write

*
  • M
NULL Pointer Dereference

*
  • H
Out-of-bounds Read

*
  • L
Out-of-bounds Read

*
  • M
Untrusted Pointer Dereference

*
  • M
Integer Underflow

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Write

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Unchecked Input for Loop Condition

*
  • M
Use of Blocking Code in Single-threaded, Non-blocking Context

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Access of Uninitialized Pointer

*
  • M
Expired Pointer Dereference

*
  • M
Improper Validation of Specified Index, Position, or Offset in Input

*
  • M
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Access of Uninitialized Pointer

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
NULL Pointer Dereference

*
  • H
Expired Pointer Dereference

*
  • M
Insufficient Granularity of Access Control

*
  • M
Buffer Overflow

*
  • M
Expired Pointer Dereference

*
  • M
Expired Pointer Dereference

*
  • M
NULL Pointer Dereference

*
  • H
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • M
Use of Uninitialized Resource

*
  • L
Incorrect Synchronization

*
  • M
Race Condition

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Integer Underflow

*
  • H
CVE-2026-89161

*
  • M
Expired Pointer Dereference

*
  • M
Improper Certificate Validation

*
  • M
Information Exposure

*
  • M
NULL Pointer Dereference

*
  • M
Resource Exhaustion

*
  • H
Out-of-bounds Write

*
  • M
Heap-based Buffer Overflow

*
  • M
CVE-2026-64535

*
  • M
Expired Pointer Dereference

*
  • M
Incorrect Resource Transfer Between Spheres

*
  • L
Out-of-bounds Read

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • M
Stack-based Buffer Overflow

*
  • H
Link Following

*
  • M
Out-of-bounds Write

*
  • M
Reachable Assertion

*
  • L
Incorrect Conversion between Numeric Types

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • H
Improper Certificate Validation

*
  • L
Integer Overflow or Wraparound

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Link Following

*
  • H
Out-of-bounds Write

*
  • H
Directory Traversal

*
  • M
Improper Access Control

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Cross-boundary Removal of Sensitive Data

*
  • M
Out-of-bounds Read

*
  • H
OS Command Injection

*
  • H
Out-of-bounds Write

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
NULL Pointer Dereference

*
  • H
Not Failing Securely ('Failing Open')

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • M
Buffer Overflow

*
  • M
Comparison Using Wrong Factors

*
  • M
Missing Initialization of Resource

*
  • H
Information Exposure

*
  • M
Buffer Overflow

*
  • H
Buffer Overflow

*
  • M
Reachable Assertion

*
  • M
Uncontrolled Recursion

*
  • M
NULL Pointer Dereference

*
  • M
Use After Free

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Link Following

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Coercion Error

*
  • L
Information Exposure

*
  • H
Authentication Bypass by Primary Weakness

*
  • M
Out-of-bounds Read

*
  • M
Reliance on Cookies without Validation and Integrity Checking

*
  • M
Authentication Bypass

*
  • M
Improper Update of Reference Count

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Use of Insufficiently Random Values

*
  • M
Use of Externally-Controlled Format String

*
  • L
Reachable Assertion

*
  • L
Origin Validation Error

*
  • M
Buffer Over-read

*
  • H
Improper Validation of Specified Type of Input

*
  • M
Exposure of Data Element to Wrong Session

*
  • L
NULL Pointer Dereference

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Directory Traversal

*
  • M
Out-of-bounds Read

*
  • M
Use After Free

*
  • M
Expired Pointer Dereference

*
  • M
CVE-2026-6368

*
  • L
Expired Pointer Dereference

*
  • L
Incorrect Calculation of Buffer Size

*
  • M
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • H
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • M
Incorrect Privilege Assignment

*
  • M
Expired Pointer Dereference

*
  • M
Directory Traversal

*
  • M
Information Exposure

*
  • M
Link Following

*
  • H
External Control of File Name or Path

*
  • H
HTTP Request Smuggling

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • M
Information Exposure

*
  • L
Incorrect Implementation of Authentication Algorithm

*
  • L
Improper Validation of Integrity Check Value

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • M
Information Exposure

*
  • L
Integer Overflow or Wraparound

*
  • M
Improper Restriction of Communication Channel to Intended Endpoints

*
  • M
Authentication Bypass

*
  • M
Out-of-bounds Read

*
  • M
Double Free

*
  • M
Use of Externally-Controlled Format String

*
  • M
Information Exposure

*
  • M
Out-of-bounds Write

*
  • M
Arbitrary Argument Injection

*
  • H
OS Command Injection

*
  • M
Improper Handling of Inconsistent Special Elements

*
  • L
Use of Uninitialized Resource

*
  • H
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • L
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • M
Link Following

*
  • H
HTTP Request Smuggling

*
  • M
Resource Exhaustion

*
  • L
Information Exposure

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Directory Traversal

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Heap-based Buffer Overflow

*
  • H
Link Following

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Heap-based Buffer Overflow

*
  • H
Link Following

*
  • M
Comparison Using Wrong Factors

*
  • M
Buffer Overflow

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • L
Out-of-bounds Read

*
  • H
Link Following

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • H
Link Following

*
  • M
Improper Preservation of Permissions

*
  • M
Expired Pointer Dereference

*
  • L
Improper Update of Reference Count

*
  • M
Cleartext Transmission of Sensitive Information

*
  • M
Improper Restriction of Excessive Authentication Attempts

*
  • M
Out-of-bounds Write

*
  • M
Off-by-one Error

*
  • M
Out-of-bounds Write

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • L
Improper Verification of Cryptographic Signature

*
  • H
Improperly Implemented Security Check for Standard

*
  • H
Link Following

*
  • M
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • M
Divide By Zero

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • M
Off-by-one Error

*
  • H
Incorrect Authorization

*
  • H
Undefined Behavior for Input to API

*
  • M
Expired Pointer Dereference

*
  • M
Improper Input Validation

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Information Exposure

*
  • M
Improper Validation of Specified Type of Input

*
  • H
Arbitrary Code Injection

*
  • M
Authentication Bypass by Primary Weakness

*
  • H
Out-of-bounds Read

*
  • L
Use of Less Trusted Source

*
  • L
Improper Certificate Validation

*
  • M
Misinterpretation of Input

*
  • H
OS Command Injection

*
  • L
Out-of-bounds Write

*
  • H
Write-what-where Condition

*
  • H
Expired Pointer Dereference

*
  • M
Incorrect Bitwise Shift of Integer

*
  • M
Out-of-bounds Read

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
HTTP Request Smuggling

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Uncontrolled Recursion

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Use After Free

*
  • H
OS Command Injection

*
  • M
Reachable Assertion

*
  • H
Improper Update of Reference Count

*
  • L
Integer Underflow

*
  • H
Link Following

*
  • M
Out-of-bounds Write

*
  • M
Reachable Assertion

*
  • H
Expired Pointer Dereference

*
  • M
Incomplete Filtering of Special Elements

*
  • M
Out-of-bounds Read

*
  • M
Incorrect Calculation of Buffer Size

*
  • L
Improper Validation of Integrity Check Value

*
  • H
Improper Control of Dynamically-Identified Variables

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Uncontrolled Recursion

*
  • H
Access of Uninitialized Pointer

*
  • M
Integer Overflow or Wraparound

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Asymmetric Resource Consumption (Amplification)

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
NULL Pointer Dereference

*
  • M
Incorrect Execution-Assigned Permissions

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
Inappropriate Encoding for Output Context

*
  • M
Out-of-bounds Read

*
  • M
Use After Free

*
  • M
Generation of Weak Initialization Vector (IV)

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Directory Traversal

*
  • H
Integer Underflow

*
  • M
Improper Null Termination

*
  • M
Integer Overflow or Wraparound

*
  • M
Link Following

*
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Off-by-one Error

*
  • H
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • H
Improper Null Termination

*
  • M
External Control of File Name or Path

*
  • M
Improper Certificate Validation

*
  • M
Improper Certificate Validation

*
  • M
Improper Input Validation

*
  • M
OS Command Injection

*
  • M
Execution with Unnecessary Privileges

*
  • M
Uncontrolled Recursion

*
  • M
OS Command Injection

*
  • M
Improper Certificate Validation

*
  • M
Directory Traversal

*
  • H
Improper Preservation of Permissions

*
  • M
Integer Overflow or Wraparound

*
  • M
OS Command Injection

*
  • H
OS Command Injection

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Incorrect Behavior Order: Early Validation

*
  • L
Improperly Implemented Security Check for Standard

*
  • M
Improper Validation of Array Index

*
  • M
Expired Pointer Dereference

*
  • M
Integer Underflow

*
  • H
Predictable from Observable State

*
  • M
Out-of-bounds Write

*
  • M
Link Following

*
  • M
Improper Handling of Case Sensitivity

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Directory Traversal

*
  • M
Expired Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • H
Time-of-check Time-of-use (TOCTOU)

*
  • L
NULL Pointer Dereference

*
  • L
Improper Verification of Cryptographic Signature

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Expired Pointer Dereference

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Heap-based Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • H
OS Command Injection

*
  • H
Expired Pointer Dereference

*
  • M
Buffer Overflow

*
  • M
Out-of-bounds Read

*
  • L
Directory Traversal

*
  • L
NULL Pointer Dereference

*
  • M
Directory Traversal

*
  • L
Integer Overflow or Wraparound

*
  • L
NULL Pointer Dereference

*
  • L
Inefficient Regular Expression Complexity

*
  • M
OS Command Injection

*
  • L
Missing Authentication for Critical Function

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Underflow

*
  • M
NULL Pointer Dereference

*
  • L
Improper Handling of Missing Special Element

*
  • L
OS Command Injection

*
  • M
Memory Leak

*
  • L
Information Exposure

*
  • H
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Read

*
  • M
Reachable Assertion

*
  • M
OS Command Injection

*
  • M
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Link Following

*
  • L
CVE-2026-28387

*
  • H
Buffer Access with Incorrect Length Value

*
  • M
Improper Access Control

*
  • L
Improper Validation of Specified Index, Position, or Offset in Input

*
  • L
Unchecked Input for Loop Condition

*
  • M
Improper Handling of Length Parameter Inconsistency

*
  • M
Out-of-bounds Read

*
  • M
Improper Validation of Consistency within Input

*
  • L
Out-of-bounds Read

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • H
Improper Handling of Length Parameter Inconsistency

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Improper Privilege Management

*
  • H
Improper Validation of Integrity Check Value

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Improper Validation of Specified Type of Input

*
  • H
OS Command Injection

*
  • M
Out-of-bounds Read

*
  • L
Out-of-bounds Write

*
  • L
Integer Overflow or Wraparound

*
  • M
Insufficient Verification of Data Authenticity

*
  • M
NULL Pointer Dereference

*
  • M
Out-of-bounds Read

*
  • H
Reachable Assertion

*
  • L
NULL Pointer Dereference

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Write

*
  • L
Misinterpretation of Input

*
  • L
NULL Pointer Dereference

*
  • L
NULL Pointer Dereference

*
  • M
Uncontrolled Recursion

*
  • L
Stack-based Buffer Overflow

*
  • H
Write-what-where Condition

*
  • H
Integer Underflow

*
  • M
Directory Traversal

*
  • M
Integer Overflow or Wraparound

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • L
Improper Validation of Specified Type of Input

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Uncontrolled Recursion

*
  • M
Memory Leak

*
  • M
Directory Traversal

*
  • L
Out-of-bounds Read

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Least Privilege Violation

*
  • M
Improper Handling of Case Sensitivity

*
  • M
Improper Use of Validation Framework

*
  • M
Link Following

*
  • M
Link Following

*
  • M
Expired Pointer Dereference

*
  • L
Stack-based Buffer Overflow

*
  • H
Use After Free

*
  • H
Out-of-bounds Read

*
  • M
Improper Validation of Consistency within Input

*
  • M
Use of Uninitialized Resource

*
  • M
Improper Validation of Integrity Check Value

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • M
Buffer Overflow

*
  • M
Integer Underflow

*
  • L
Expired Pointer Dereference

*
  • L
Use of Uninitialized Resource

*
  • M
Improper Neutralization of Null Byte or NUL Character

*
  • L
Out-of-bounds Read

*
  • L
Improper Null Termination

*
  • M
Out-of-bounds Read

*
  • H
Insufficient Verification of Data Authenticity

*
  • M
Use After Free

*
  • H
Insecure Default Initialization of Resource

*
  • M
NULL Pointer Dereference

*
  • M
Reachable Assertion

*
  • M
Link Following

*
  • M
Resource Exhaustion

*
  • L
Out-of-bounds Write

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
OS Command Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Read

*
  • H
Resource Exhaustion

*
  • L
External Control of File Name or Path

*
  • M
Buffer Underflow

*
  • M
Use After Free

*
  • H
Reachable Assertion

*
  • M
Uncontrolled Recursion

*
  • M
Buffer Overflow

*
  • L
Reachable Assertion

*
  • L
Memory Leak

*
  • L
Uncontrolled Recursion

*
  • M
Reachable Assertion

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • L
Integer Overflow or Wraparound

*
  • H
Out-of-bounds Read

*
  • L
External Control of System or Configuration Setting

*
  • M
Buffer Overflow

*
  • H
Access of Uninitialized Pointer

*
  • M
Incorrect Calculation of Buffer Size

*
  • H
Numeric Truncation Error

*
  • M
Improper Handling of Insufficient Permissions or Privileges

*
  • M
Reachable Assertion

*
  • L
Access of Uninitialized Pointer

*
  • M
Improper Validation of Specified Type of Input

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Integer Underflow

*
  • M
Expired Pointer Dereference

*
  • M
Out-of-bounds Write

*
  • M
Buffer Underflow

*
  • M
Improper Certificate Validation

*
  • M
Permissive Regular Expression

*
  • H
Execution with Unnecessary Privileges

*
  • L
Out-of-bounds Read

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • L
Out-of-bounds Read

*
  • M
Double Free

*
  • H
Out-of-bounds Write

*
  • L
Incorrect Calculation of Buffer Size

*
  • H
Resource Exhaustion

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Double Free

*
  • M
Release of Invalid Pointer or Reference

*
  • L
Use of Uninitialized Resource

*
  • M
Expired Pointer Dereference

*
  • L
Out-of-bounds Write

*
  • L
NULL Pointer Dereference

*
  • M
Buffer Overflow

*
  • L
Out-of-bounds Read

*
  • H
Out-of-bounds Read

*
  • M
Incorrect Calculation

*
  • H
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • L
Unchecked Input for Loop Condition

*
  • L
Algorithmic Complexity

*
  • M
NULL Pointer Dereference

*
  • H
Improper Access Control

*
  • M
Out-of-bounds Read

*
  • M
NULL Pointer Dereference

*
  • L
Incorrect Calculation of Multi-Byte String Length

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Untrusted Search Path

*
  • M
Expired Pointer Dereference

*
  • M
Directory Traversal

*
  • L
Integer Overflow or Wraparound

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Use After Free

*
  • M
Out-of-bounds Read

*
  • H
CRLF Injection

*
  • L
Out-of-bounds Write

*
  • M
Directory Traversal

*
  • H
Symlink Following

*
  • M
Expired Pointer Dereference

*
  • L
Resource Exhaustion

*
  • H
Improper Authentication

*
  • M
NULL Pointer Dereference

*
  • M
Return of Wrong Status Code

*
  • M
Buffer Overflow

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Stack-based Buffer Overflow

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • H
Improper Validation of Consistency within Input

*
  • L
Out-of-bounds Read

*
  • M
Directory Traversal

*
  • L
Arbitrary Argument Injection

*
  • M
Directory Traversal

*
  • M
Information Exposure

*
  • M
Insufficient Granularity of Access Control

*
  • M
Out-of-bounds Read

*
  • L
Heap-based Buffer Overflow

*
  • M
Unrestricted Externally Accessible Lock

*
  • M
Return of Wrong Status Code

*
  • M
Reachable Assertion

*
  • L
Stack-based Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Out-of-Bounds

*
  • M
Buffer Overflow

*
  • H
Expired Pointer Dereference

*
  • M
OS Command Injection

*
  • M
Incorrect Calculation of Buffer Size

*
  • M
Out-of-bounds Write

*
  • L
Stack-based Buffer Overflow

*
  • M
Expected Behavior Violation

*
  • M
CVE-2025-61662

*
  • M
Out-of-bounds Read

*
  • L
Buffer Overflow

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Failure to Sanitize Special Element

*
  • M
Use After Free

*
  • M
Integer Overflow or Wraparound

*
  • M
Out-of-bounds Write

*
  • M
Processor Optimization Removal or Modification of Security-critical Code

*
  • M
Unchecked Input for Loop Condition

*
  • L
Missing Required Cryptographic Step

*
  • L
Improper Validation of Specified Quantity in Input

*
  • M
Out-of-Bounds

*
  • H
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Reversible One-Way Hash

*
  • M
Buffer Over-read

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • M
Out-of-bounds Read

*
  • M
Uncontrolled Search Path Element

*
  • M
Incorrect Privilege Assignment

*
  • M
Improper Certificate Validation

*
  • L
NULL Pointer Dereference

*
  • H
Incorrect Privilege Assignment

*
  • M
Out-of-bounds Write

*
  • M
Algorithmic Complexity

*
  • H
Incorrect Authorization

*
  • L
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Integer Overflow or Wraparound

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Information Exposure

*
  • L
NULL Pointer Dereference

*
  • L
Out-of-bounds Write

*
  • H
Incorrect Privilege Assignment

*
  • L
Improper Certificate Validation

*
  • L
Improperly Implemented Security Check for Standard

*
  • H
Improper Verification of Cryptographic Signature

*
  • H
Resource Exhaustion

*
  • M
Arbitrary Argument Injection

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Out-of-bounds Write

*
  • H
Out-of-bounds Read

*
  • M
Use of Out-of-range Pointer Offset

*
  • H
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • M
Out-of-bounds Write

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Validation of Specified Quantity in Input

*
  • L
Out-of-bounds Read

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Invokable Control Element in Multi-Thread Context with non-Final Static Storable or Member Element

*
  • L
Authentication Bypass by Primary Weakness

*
  • M
Information Exposure

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • M
Use of Uninitialized Resource

*
  • M
Out-of-bounds Read

*
  • L
Use of Uninitialized Resource

*
  • M
NULL Pointer Dereference

*
  • L
Unchecked Return Value

*
  • H
Buffer Overflow

*
  • H
CRLF Injection

*
  • L
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • M
Expired Pointer Dereference

*
  • M
Use After Free

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • H
Stack-based Buffer Overflow

*
  • L
NULL Pointer Dereference

*
  • M
Acceptance of Extraneous Untrusted Data With Trusted Data

*
  • M
Heap-based Buffer Overflow

*
  • M
Double Free

*
  • M
Improper Certificate Validation

*
  • L
NULL Pointer Dereference

*
  • L
Buffer Access with Incorrect Length Value

*
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • H
Out-of-bounds Write

*
  • H
Use of Uninitialized Resource

*
  • M
Improper Handling of Parameters

*
  • H
Out-of-bounds Write

*
  • H
Directory Traversal

*
  • M
Out-of-bounds Write

*
  • M
Incorrect Execution-Assigned Permissions

*
  • H
NULL Pointer Dereference

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Use After Free

*
  • M
Missing Authentication for Critical Function

*
  • M
Improper Synchronization

*
  • M
Out-of-bounds Write

*
  • H
Improper Input Validation

*
  • L
NULL Pointer Dereference

*
  • M
CVE-2024-26602

*
  • M
Stack-based Buffer Overflow

*
  • L
Out-of-Bounds

*
  • L
Out-of-bounds Read

*
  • H
Use After Free

*
  • H
Improper Authentication

*
  • H
Improper Privilege Management

*
  • M
Insufficiently Protected Credentials

*
  • H
Race Condition

*
  • L
Out-of-bounds Write

*
  • H
Reachable Assertion

*
  • M
Out-of-bounds Read

*
  • H
Use After Free

*
  • H
Buffer Overflow

*
  • H
Out-of-bounds Write

*
  • M
Integer Overflow or Wraparound

*
  • H
Symlink Following

*
  • L
Out-of-bounds Read

*
  • H
Resource Exhaustion

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Resource Exhaustion

*
  • M
Buffer Overflow

*
  • M
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

*
  • H
Resource Exhaustion

*
  • M
Information Exposure

*
  • M
NULL Pointer Dereference

*
  • M
HTTP Request Smuggling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Out-of-bounds Read

*
  • M
Expired Pointer Dereference

*
  • H
Out-of-bounds Write

*
  • H
Integer Overflow or Wraparound

*
  • M
NULL Pointer Dereference

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*