CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

130 vulnerabilities with CWE-670
CVE-2026-41988 LOW
uuid <14.0.0 - Memory Corruption
CVSS 3.2
CVE-2026-35343 LOW
uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters
CVSS 3.3
CVE-2026-41527 MEDIUM
KDE Kleopatra <26.08.0 - Privilege Escalation
CVSS 6.9
CVE-2026-40942 MEDIUM
DSF: Inverted Time Comparison in OIDC JWKS and Token Cache
CVE-2026-6608 MEDIUM
lm-sys fastchat Arena Side-by-Side View add_text control flow
CVSS 5.3
CVE-2026-40960 HIGH
Luanti <5.15.2 - Privilege Escalation
CVSS 8.1
CVE-2026-40719 HIGH
MaraDNS 3.5.0036 - DoS
CVSS 7.5
CVE-2026-40396 MEDIUM
Varnish-software Varnish Cache < 9.0.1 - Denial of Service
CVSS 4.0
CVE-2026-40394 MEDIUM
Varnish-software Varnish Cache < 9.0.1 - Denial of Service
CVSS 4.0
CVE-2026-40200 HIGH
musl libc 0.7.10-1.2.6 - Memory Corruption
CVSS 8.1
CVE-2026-34946 HIGH
Wasmtime's host panics when Winch compiler executes `table.fill`
CVSS 7.5
CVE-2026-35414 MEDIUM
OpenSSH <10.3 - Auth Bypass
CVSS 4.2
CVE-2026-35387 LOW
OpenSSH <10.3 - ECDSA Algorithm Misinterpretation
CVSS 3.1
CVE-2026-33011 HIGH
Nest Fastify HEAD Request Middleware Bypass
CVE-2026-32713 MEDIUM
PX4 Autopilot <1.17.0-rc2 - Auth Bypass
CVSS 4.3
CVE-2026-1874 HIGH
MELSEC iQ-F FX5-ENET/IP <=1.106 - DoS
CVE-2026-26267 HIGH
soroban-sdk <22.0.10/23.5.2/25.1.1 - Code Injection
CVSS 7.5
CVE-2025-58136 HIGH
Apache Traffic Server: A simple legitimate POST request causes a crash
CVSS 7.5
CVE-2025-33199 LOW
NVIDIA DGX Spark GB10 - Memory Corruption
CVSS 3.2
CVE-2025-32942 HIGH
SSH Tectia Server <6.6.6 - Info Disclosure
CVSS 7.2
CVE-2025-43359 CRITICAL
tvOS 26 - Info Disclosure
CVSS 9.8
CVE-2025-38291 MEDIUM
Linux Kernel - Info Disclosure
CVSS 5.5
CVE-2025-49091 HIGH
KDE Konsole <25.04.2 - RCE
CVSS 8.2
CVE-2025-32996 MEDIUM
http-proxy-middleware <2.0.8, <3.0.4 - Info Disclosure
CVSS 4.0
CVE-2025-2886 MEDIUM
Tough <0.20.0 - Info Disclosure
CVSS 4.5
Details
Vulnerabilities 130