CWE-670

Always-Incorrect Control Flow Implementation

Parent: CWE-691 - Insufficient Control Flow Management

The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.

142 vulnerabilities with CWE-670
CVE-2026-16392 CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component
CVSS 9.1
CVE-2026-14935 LOW
Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check
CVSS 3.7
CVE-2026-56328 MEDIUM
Capgo < 12.128.2 - Public Channel Release Routing Integrity Issue
CVSS 6.5
CVE-2026-7656 HIGH
Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
CVSS 8.1
CVE-2026-55276 CRITICAL
Apache Tomcat: Logged effective web.xml is incomplete
CVSS 9.1
CVE-2026-53404 HIGH
Apache Tomcat: Bad ornext processing in RewriteValve
CVSS 7.3
CVE-2026-56307 MEDIUM
Cap-go - Broken Cursor Pagination in /private/devices Endpoint
CVSS 4.3
CVE-2026-12321 MEDIUM
JIT miscompilation in the JavaScript: WebAssembly component
CVSS 5.4
CVE-2026-48844 HIGH
Roundcube Webmail - Always-Incorrect Control Flow Implementation
CVSS 7.5
CVE-2026-20171 MEDIUM
Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability
CVSS 6.8
CVE-2026-38361 HIGH
dash-uploader 0.1.0-0.7.0a2 Upload Handler - Remote Code Execution
CVSS 7.5
CVE-2026-44928 LOW
uriparser < 1.0.2 - Always-Incorrect Control Flow Implementation in EqualsUri Function
CVSS 2.9
CVE-2026-41988 LOW
uuidjs/uuid < 14.0.0 - Unexpected Buffer Writes via UUID v3/5/6 Generation
CVSS 3.2
CVE-2026-35343 LOW
uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters
CVSS 3.3
CVE-2026-41527 MEDIUM
KDE Kleopatra <26.08.0 - Privilege Escalation
CVSS 6.9
CVE-2026-40942 MEDIUM
DSF: Inverted Time Comparison in OIDC JWKS and Token Cache
CVE-2026-6608 MEDIUM
lm-sys fastchat Arena Side-by-Side View add_text control flow
CVSS 5.3
CVE-2026-40960 HIGH
Luanti <5.15.2 - Privilege Escalation
CVSS 8.1
CVE-2026-40719 HIGH
MaraDNS 3.5.0036 - Denial of Service via Unresolvable Authoritative Nameserver
CVSS 7.5
CVE-2026-40396 MEDIUM
Varnish Cache 9.0.0 - Denial of Service via HTTP/1 Pipelining Workspace Overflow
CVSS 4.0
CVE-2026-40394 MEDIUM
Varnish Cache 9.0.0-9.0.0 and Varnish Enterprise < 6.0.16r11 - Denial of Service via HTTP/2 Session Upgrade
CVSS 4.0
CVE-2026-40200 HIGH
musl libc 0.7.10-1.2.6 - Memory Corruption
CVSS 8.1
CVE-2026-34946 HIGH
Wasmtime's host panics when Winch compiler executes `table.fill`
CVSS 7.5
CVE-2026-35414 MEDIUM
OpenSSH < 10.3 - Always-Incorrect Control Flow Implementation in Authorized Keys Principals Handling
CVSS 4.2
CVE-2026-35387 LOW
OpenSSH <10.3 - ECDSA Algorithm Misinterpretation
CVSS 3.1
Details
Vulnerabilities 142