CWE-129

High likelihood

Improper Validation of Array Index

Parent: CWE-1285 - Improper Validation of Specified Index, Position, or Offset in Input

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

556 vulnerabilities with CWE-129
CVE-2026-40886 HIGH
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller
CVSS 7.7
CVE-2026-6840 MEDIUM
Samsung ONE <1.30.0 - Memory Corruption
CVSS 5.5
CVE-2026-40097 LOW
Step CA affected by an index out of bounds panic in TPM attestation EKU validation
CVSS 3.7
CVE-2026-34942 MEDIUM
Wasmtime panics when transcoding misaligned utf-16 strings
CVSS 6.5
CVE-2026-21413 CRITICAL
LibRaw < Commit 0b56545 - Buffer Overflow
CVSS 9.8
CVE-2026-23447 HIGH
net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
CVSS 7.8
CVE-2026-33762 LOW
go-git: Missing validation decoding Index v4 files leads to panic
CVSS 2.8
CVE-2026-32285 HIGH
Denial of service in github.com/buger/jsonparser
CVSS 7.5
CVE-2026-23354 HIGH
x86/fred: Correct speculative safety in fred_extint()
CVSS 7.8
CVE-2026-33281 MEDIUM
Ella Core <1.6.0 - DoS
CVSS 6.5
CVE-2026-33022 MEDIUM
Tekton Pipelines: Controller can panic when setting long resolver names in TaskRun/PipelineRun
CVSS 6.5
CVE-2026-32937 MEDIUM
free5GC CHF has Out-of-Bounds Slice Access that Leads to DoS
CVSS 6.5
CVE-2026-26933 MEDIUM
Improper Validation of Array Index in Packetbeat Leading to Denial of Service
CVSS 5.7
CVE-2026-4427 HIGH
Github.com/jackc/pgproto3: pgproto3: denial of service via negative field length in datarow message
CVSS 7.5
CVE-2026-31967 CRITICAL
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
CVSS 9.1
CVE-2026-31966 CRITICAL
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
CVSS 9.1
CVE-2026-31965 HIGH
HTSlib CRAM reader has out-of-bounds reads due to improper validation of input
CVSS 8.2
CVE-2026-31963 HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.1
CVE-2026-31962 HIGH
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
CVSS 8.8
CVE-2026-3083 HIGH
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-30984 MEDIUM
iccDEV <2.3.1.5 - Memory Corruption
CVSS 6.1
CVE-2026-30982 MEDIUM
iccDEV <2.3.1.5 - Memory Corruption
CVSS 6.1
CVE-2026-26932 MEDIUM
Packetbeat - DoS
CVSS 5.7
CVE-2026-25882 HIGH
Fiber v2/v3 - DoS
CVSS 7.5
CVE-2026-2006 HIGH
PostgreSQL <18.2-14.21 - RCE
CVSS 8.8
Details
Vulnerabilities 556
Exploit Likelihood High