The product uses an algorithm that produces a digest (output value) that does not meet security expectations for a hash function that allows an adversary to reasonably determine the original input (preimage attack), find another input that can produce the same hash (2nd preimage attack), or find multiple inputs that evaluate to the same hash (birthday attack).
90 vulnerabilities with CWE-328
CVE-2026-15605
LOW
wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
CVSS 3.1
CVE-2026-41879
HIGH
Weak password hashing in R-SOFT DMS
CVE-2026-14742
LOW
langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
CVSS 3.1
CVE-2026-14738
LOW
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
CVSS 3.7
CVE-2026-14630
LOW
ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
CVSS 3.1
CVE-2026-10540
MEDIUM
Weak password hash protection in Control-M/Entreprise Manager
CVSS 5.6
CVE-2026-13455
MEDIUM
PostgreSQL Anonymizer: Unrestricted function can leak the secret salt
CVSS 4.3
CVE-2026-53692
MEDIUM
Weak hahshing algorithm in Redeight CMS
CVE-2026-13510
LOW
SimStudioAI sim Password Protection deployment.ts weak hash
CVSS 3.7
CVE-2026-13482
LOW
skypilot-org skypilot User ID server.py username.encode weak hash
CVSS 3.7
CVE-2026-54266
MEDIUM
Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
CVSS 6.1
CVE-2026-48488
LOW
phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing
CVE-2026-11481
LOW
yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash
CVSS 2.5
CVE-2026-11479
MEDIUM
yoanbernabeu grepai Qdrant Backend chunker.go weak hash
CVSS 4.2
CVE-2026-11330
LOW
thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash
CVSS 3.6
CVE-2026-11329
LOW
onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash
CVSS 3.6
CVE-2026-36182
CRITICAL
GNCC GP5 v7.1.76 - Weak Hashing Algorithm for Root Password
CVSS 9.8
CVE-2026-10814
MEDIUM
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
CVSS 4.5
CVE-2026-10813
LOW
LMCache KV Cache utils.py hex_hash_to_int16 weak hash
CVSS 3.6
CVE-2026-10812
LOW
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
CVSS 3.6
CVE-2026-10804
LOW
Streamlit Palette hashing.py weak hash
CVSS 3.6
CVE-2026-10803
LOW
MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash
CVSS 3.6
CVE-2026-10801
LOW
modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash
CVSS 3.6
CVE-2026-10800
LOW
PaddlePaddle FastDeploy MultimodalHasher hasher.py hash_features weak hash
CVSS 3.6
CVE-2026-10783
LOW
gradio-app gradio Audio Cache Key save_audio_to_cache weak hash
CVSS 2.5
Details
Vulnerabilities
90