CWE-184

Incomplete List of Disallowed Inputs

Parent: CWE-693 - Protection Mechanism Failure

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

161 vulnerabilities with CWE-184
CVE-2026-18174 MEDIUM
@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For
CVSS 5.3
CVE-2026-50251 MEDIUM
Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVSS 5.3
CVE-2026-47392 CRITICAL
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CVSS 9.9
CVE-2026-63108 HIGH
Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing
CVSS 8.8
CVE-2026-16129 MEDIUM
princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist
CVSS 5.3
CVE-2026-13448 HIGH
Langflow Oss < 1.10.1 - Remote Code Execution
CVSS 8.1
CVE-2026-62203 HIGH
OpenClaw < 2026.6.6 Environment Variable Injection via rustup
CVSS 8.8
CVE-2026-52888 MEDIUM
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
CVSS 6.8
CVE-2026-48736 HIGH
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
CVSS 8.6
CVE-2026-45753 MEDIUM
Symfony HtmlSanitizer - Cross-Site Scripting via Unsanitized URL Attributes
CVSS 6.1
CVE-2026-45066 MEDIUM
Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
CVSS 6.1
CVE-2026-15625 MEDIUM
nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist
CVSS 6.3
CVE-2026-62200 HIGH
OpenClaw < 2026.6.6 Authentication Bypass via Git ext transport
CVSS 8.8
CVE-2026-62199 HIGH
OpenClaw < 2026.6.6 Authentication Bypass via Environment Filtering
CVSS 8.8
CVE-2026-55830 HIGH
RestrictedPython guard hooks can be shadowed via positional-only arguments
CVSS 8.3
CVE-2026-59929 MEDIUM
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
CVSS 6.1
CVE-2026-59261 HIGH
OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
CVSS 7.1
CVE-2026-14534 HIGH
Fickling check_safety() bypass via unlisted standard library modules (_posixsubprocess, site, atexit)
CVSS 8.8
CVE-2026-56777 MEDIUM
n8n - AST Validator Bypass in Python Code Node
CVSS 5.0
CVE-2026-49869 CRITICAL
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
CVSS 10.0
CVE-2026-54090 HIGH
File Browser: Command Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-57234 LOW
Nokogiri JRuby < 1.19.4 - NONET Bypass Allows Network Requests
CVSS 2.6
CVE-2026-54070 HIGH
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
CVSS 7.1
CVE-2026-47389 HIGH
Mastodon: SSRF protection bypass on older Ruby versions
CVSS 8.6
CVE-2026-53944 MEDIUM
Ghost: Private IP filtering bypass to make server-side requests to internal services
CVSS 5.8
Details
Vulnerabilities 161