CWE-1286
Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
88 vulnerabilities with CWE-1286
CVE-2026-57026
HIGH
Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
CVSS 7.5
CVE-2026-55767
MEDIUM
Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
CVSS 5.8
CVE-2026-48059
HIGH
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
CVSS 7.5
CVE-2026-50131
HIGH
Fedify validatePublicUrl - Special-Use IPv4 Server-Side Request Forgery Bypass
CVSS 8.6
CVE-2026-24092
HIGH
Qualcomm Snapdragon Display - Fastboot Display Mode Memory Corruption
CVSS 7.2
CVE-2026-24091
HIGH
Qualcomm Snapdragon Display - Fastboot Input Validation Memory Corruption
CVSS 7.2
CVE-2026-24089
HIGH
Qualcomm Snapdragon Kernel - Fastboot Invalid Input Memory Corruption
CVSS 7.2
CVE-2026-24087
HIGH
Qualcomm Snapdragon Kernel - Fastboot OEM Command Memory Corruption
CVSS 7.2
CVE-2026-10099
MEDIUM
XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py
CVSS 4.0
CVE-2026-7307
HIGH
Keycloak: keycloak: denial of service via specially crafted saml input
CVSS 7.5
CVE-2026-0983
HIGH
M-Files Server Before 26.5.16015.0 - Authenticated Denial of Service
CVE-2026-42579
HIGH
Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
CVSS 7.5
CVE-2026-6918
HIGH
Eclipse OpenJ9 0.21-0.58 - Unauthenticated Denial of Service via Crafted TCP Message
CVSS 7.5
CVE-2026-6442
HIGH
Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface
CVSS 8.3
CVE-2026-40198
HIGH
Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass
CVSS 7.5
CVE-2026-33778
HIGH
Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received kmd/iked crashes
CVSS 7.5
CVE-2026-34835
MEDIUM
Rack: `Rack::Request` accepts invalid Host characters, enabling host allowlist bypass.
CVSS 4.8
CVE-2026-33218
HIGH
NATS has pre-auth server panic via leafnode handling
CVSS 7.5
CVE-2026-27889
HIGH
NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
CVSS 7.5
CVE-2026-20114
MEDIUM
Cisco IOS XE Software <16.11.1 - Privilege Escalation
CVSS 5.4
CVE-2026-3632
LOW
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVSS 3.9
CVE-2026-25679
HIGH
Go standard library net/url < 1.25.8 and 1.26.0 - Direct Request via Invalid URL Host Parsing
CVSS 7.5
CVE-2026-21527
MEDIUM
Microsoft Exchange Server - Info Disclosure
CVSS 6.5
CVE-2026-25513
HIGH
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8
CVE-2026-0663
MEDIUM
M-Files Server < 26.1.15632.3 - Authenticated Denial of Service via API Endpoint
CVSS 4.9
Details
Vulnerabilities
88