CWE-1287

Improper Validation of Specified Type of Input

Parent: CWE-20 - Improper Input Validation

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

146 vulnerabilities with CWE-1287
CVE-2026-4773 HIGH
OTP Bypass in Magarsus' IDM-MFA
CVSS 8.1
CVE-2026-50524 HIGH
Microsoft .NET and Visual Studio - Network Denial of Service via Input Validation
CVSS 7.5
CVE-2026-45069 CRITICAL
Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
CVSS 9.1
CVE-2026-55124 MEDIUM
Microsoft Word Information Disclosure Vulnerability
CVSS 5.5
CVE-2026-44935 CRITICAL
Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer
CVSS 9.9
CVE-2026-54235 MEDIUM
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
CVSS 6.5
CVE-2026-10825 HIGH
Improper JSON Input Validation in WebSocket API Leads to Denial of Service
CVE-2026-44249 HIGH
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
CVSS 8.1
CVE-2026-9753 HIGH
Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.
CVSS 8.1
CVE-2026-9742 HIGH
Authenticate command with specific mechanism parameter can trigger server crash
CVSS 7.5
CVE-2026-11460 HIGH
Boost Serialization improper validation of specified type of input
CVSS 7.3
CVE-2026-49941 HIGH
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses
CVSS 7.5
CVE-2026-47675 MEDIUM
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
CVSS 4.3
CVE-2026-40851 HIGH
Command injection via USB
CVSS 8.4
CVE-2026-9521 HIGH
fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type of input
CVSS 7.3
CVE-2026-4646 MEDIUM
Insufficient input validation in GitHub plugin API causes denial of service
CVSS 4.3
CVE-2026-7887 MEDIUM
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status
CVSS 6.4
CVE-2026-5946 HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-0802 MEDIUM
Axis Communications AB Axis OS < 12.9.33 - Improper Validation of Specified Type of Input
CVSS 6.0
CVE-2026-29645 HIGH
NEMU <v2025.12.r2 - Instruction Validation Flaw
CVSS 7.5
CVE-2026-33806 HIGH
fastify vulnerable to Body Schema Validation Bypass via Leading Space in Content-Type Header
CVSS 7.5
CVE-2026-4598 HIGH
jsrsasign < 11.1.1 - Denial of Service via Infinite Loop in bnModInverse
CVSS 7.5
CVE-2026-2092 HIGH
Keycloak-services: keycloak: unauthorized access via improper validation of encrypted saml assertions
CVSS 7.7
CVE-2026-2454 MEDIUM
DoS in Calls plugin via malformed msgpack in websocket request.
CVSS 5.8
CVE-2026-25783 MEDIUM
Denial of service via malformed User-Agent header in getBrowserVersion
CVSS 4.3
Details
Vulnerabilities 146