CWE-328

Use of Weak Hash

Parent: CWE-326 - Inadequate Encryption Strength

The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).

79 vulnerabilities with CWE-328
CVE-2026-48488 LOW
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
CVE-2026-11481 LOW
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
CVSS 2.5
CVE-2026-11479 MEDIUM
yoanbernabeu grepai Qdrant Backend chunker.go weak hash
CVSS 4.2
CVE-2026-11330 LOW
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
CVSS 3.6
CVE-2026-11329 LOW
onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash
CVSS 3.6
CVE-2026-36182 CRITICAL
GNCC GP5 v7.1.76 - Weak Hashing Algorithm for Root Password
CVSS 9.8
CVE-2026-10814 MEDIUM
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
CVSS 4.5
CVE-2026-10813 LOW
LMCache KV Cache utils.py hex_hash_to_int16 weak hash
CVSS 3.6
CVE-2026-10812 LOW
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
CVSS 3.6
CVE-2026-10804 LOW
Streamlit Palette hashing.py weak hash
CVSS 3.6
CVE-2026-10803 LOW
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
CVSS 3.6
CVE-2026-10801 LOW
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
CVSS 3.6
CVE-2026-10800 LOW
PaddlePaddle FastDeploy MultimodalHasher hasher.py hash_features weak hash
CVSS 3.6
CVE-2026-10783 LOW
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
CVSS 2.5
CVE-2026-10766 LOW
mlrun DataFrame Hash helpers.py mlrun.utils.helpers.calculate_dataframe_hash weak hash
CVSS 3.6
CVE-2026-45413 MEDIUM
MaxKB: Unsalted MD5 Password Hashing
CVE-2026-8803 LOW
opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hash
CVSS 3.7
CVE-2026-44582 LOW
Next.js: Cache poisoning via collisions in React Server Component cache-busting
CVSS 3.7
CVE-2026-34527 MEDIUM
Sandboxie-Plus EditPassword hash entropy reduced from 160 bits to 80 bits due to incorrect nibble extraction
CVSS 5.3
CVE-2026-7845 LOW
chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hash
CVSS 2.6
CVE-2026-7103 LOW
code-projects Chat System MD5 Hash update_user.php weak hash
CVSS 3.7
CVE-2026-40164 HIGH
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVSS 7.5
CVE-2026-21717 MEDIUM
Node.js 20.x 22.x 24.x 25.x - Denial of Service via V8 String Hash Collision
CVSS 5.9
CVE-2026-32129 HIGH
soroban-poseidon < 25.0.1 - Hash Collision via Implicit Zero-Filling in PoseidonSponge
CVE-2026-27754 MEDIUM
SODOLA SL902-SWTGW124AS Firmware <200.1.20 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities 79