CWE-436
Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
126 vulnerabilities with CWE-436
CVE-2026-14643
MEDIUM
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
CVSS 5.9
CVE-2026-67201
HIGH
V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
CVSS 8.6
CVE-2026-49332
HIGH
Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams
CVSS 8.5
CVE-2026-16221
HIGH
fast-uri vulnerable to host confusion via literal backslash authority delimiter
CVSS 7.5
CVE-2026-63030
CRITICAL
KEV
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
CVSS 9.8
CVE-2026-44974
HIGH
Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters
CVE-2026-47767
CRITICAL
Symfony Runtime - APP_ENV/APP_DEBUG Override via SAPI Argv Mismatch
CVSS 9.8
CVE-2026-45066
MEDIUM
Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
CVSS 6.1
CVE-2026-56329
MEDIUM
Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding
CVSS 6.4
CVE-2026-56669
HIGH
Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
CVSS 7.5
CVE-2026-59882
MEDIUM
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
CVSS 4.2
CVE-2026-14198
CRITICAL
@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
CVSS 9.1
CVE-2026-13676
HIGH
fast-uri vulnerable to host confusion via failed IDN canonicalization
CVSS 7.5
CVE-2026-53538
LOW
Python-Multipart: Semicolon treated as querystring field separator enables parameter smuggling
CVSS 3.7
CVE-2026-53537
LOW
Python-Multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVSS 3.7
CVE-2026-53655
MEDIUM
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
CVSS 5.5
CVE-2026-48788
HIGH
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
CVSS 8.2
CVE-2026-42462
HIGH
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
CVSS 7.0
CVE-2026-47344
LOW
TYPO3 HTML Sanitizer allows Cross-Site Scripting
CVE-2026-40930
MEDIUM
LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body
CVSS 5.4
CVE-2026-47076
MEDIUM
SSRF allowlist bypass via percent-encoded host in hackney
CVSS 6.5
CVE-2026-40165
HIGH
authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation
CVSS 8.7
CVE-2026-42551
HIGH
Flight: HTTP method override enabled by default enables CSRF escalation and middleware bypass in flightphp/core
CVSS 7.5
CVE-2026-44576
MEDIUM
Next.js: Cache poisoning in React Server Component responses
CVSS 5.4
CVE-2026-42177
MEDIUM
linux-entra-sso: PRT SSO cookie can leak to attacker-controlled hosts when broad host permissions are granted
CVSS 5.3
Details
Vulnerabilities
126