CWE-436

Interpretation Conflict

Parent: CWE-435 - Improper Interaction Between Multiple Correctly-Behaving Entities

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

126 vulnerabilities with CWE-436
CVE-2026-42274 HIGH
Heimdall: Authorization bypass via path normalization mismatch
CVE-2026-42273 HIGH
Heimdall: Case-sensitive host matching may lead to policy bypass
CVE-2026-42272 HIGH
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
CVE-2026-8034 CRITICAL
Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion
CVSS 9.8
CVE-2026-30246 MEDIUM
github.com/gofiber/fiber/v3 cache middleware can mix responses across query parameters
CVSS 6.5
CVE-2026-6322 HIGH
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
CVSS 7.5
CVE-2026-41248 CRITICAL
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
CVSS 9.1
CVE-2026-33804 HIGH
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
CVSS 7.4
CVE-2026-6270 CRITICAL
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
CVSS 9.1
CVE-2026-33808 CRITICAL
@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
CVSS 9.1
CVE-2026-33807 CRITICAL
@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes
CVSS 9.1
CVE-2026-35200 MEDIUM
Parse Server File Uploads - Content-Type Override
CVSS 5.4
CVE-2026-32762 MEDIUM
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
CVSS 4.8
CVE-2026-26961 LOW
Rack: Multipart Boundary Parsing Ambiguity allowing WAF Bypass
CVSS 3.7
CVE-2026-32065 MEDIUM
OpenClaw < 2026.2.25 - Approval Identity Mismatch in system.run Command Execution
CVSS 4.8
CVE-2026-32052 MEDIUM
OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers
CVSS 6.4
CVE-2026-32766 MEDIUM
astral-tokio-tar insufficiently validates PAX extensions during extraction
CVSS 5.3
CVE-2026-27444 HIGH
SEPPmail Secure Email Gateway <15.0.1 - Auth Bypass
CVSS 7.5
CVE-2026-27896 HIGH
modelcontextprotocol/go-sdk < 1.3.1 - JSON-RPC Field Case Sensitivity Bypass via Non-Standard Casing
CVSS 7.5
CVE-2026-0958 HIGH
GitLab 18.4-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Unauthenticated Denial of Service via JSON Validation Middleware Bypass
CVSS 7.5
CVE-2026-23686 LOW
SAP NetWeaver Application Server Java - CRLF Injection
CVSS 3.4
CVE-2026-25223 HIGH
fastify < 5.7.2 - Request Body Validation Bypass via Content-Type Header Tab Injection
CVSS 7.5
CVE-2025-66490 MEDIUM
Traefik < 2.11.32 and 3.0.0-3.6.2 - Path Normalization Bypass via URL-Encoded Characters
CVSS 6.5
CVE-2025-12816 HIGH
node-forge < 1.3.2 - Unauthenticated ASN.1 Interpretation Conflict via Schema Desynchronization
CVSS 8.6
CVE-2025-54368 MEDIUM
Pypi UV < 0.8.6 - Interpretation Conflict
Details
Vulnerabilities 126