CWE-704

Incorrect Type Conversion or Cast

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not correctly convert an object, resource, or structure from one type to a different type.

273 vulnerabilities with CWE-704
CVE-2026-50337 HIGH
Microsoft Windows 10 Version 1607 - Windows Notification Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-59871 MEDIUM
node-tar: Process crash via PAX numeric path type confusion
CVSS 5.3
CVE-2026-55076 HIGH
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
CVSS 7.4
CVE-2026-48140 MEDIUM
NI grpc-device <= 2.17.0 BeginSidebandStream - Denial of Service
CVSS 6.5
CVE-2026-46690 MEDIUM
unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
CVSS 5.8
CVE-2026-45685 HIGH
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
CVSS 7.5
CVE-2026-44324 MEDIUM
free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
CVSS 6.5
CVE-2026-46597 HIGH
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
CVSS 7.5
CVE-2026-44223 MEDIUM
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
CVSS 6.5
CVE-2026-42576 MEDIUM
apko <1.2.7 DiscoverKeys - Denial of Service
CVSS 6.5
CVE-2026-40613 HIGH
Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)
CVSS 7.5
CVE-2026-34379 HIGH
OpenEXR DWA/DWAB LossyDctDecoder - Misaligned Write
CVSS 7.1
CVE-2026-27809 CRITICAL
psd-tools < 1.12.2 - Denial of Service via Malformed RLE-Compressed Image Data
CVSS 9.1
CVE-2026-25613 MEDIUM
MongoDB 7.0.0-7.0.28 - Denial of Service via Invalid Compound Wildcard Index Query
CVSS 6.5
CVE-2026-25518 MEDIUM
cert-manager 1.18.0-1.18.4 and 1.19.0-1.19.2 - Denial of Service via ACME DNS-01 Processing
CVSS 5.9
CVE-2026-25503 HIGH
iccdev < 2.3.1.2 - Denial of Service via Malformed ICC Profile
CVSS 7.1
CVE-2026-24856 HIGH
iccDEV < 2.3.1.2 - Memory Corruption via Floating-Point NaN to Unsigned Short Conversion
CVSS 7.8
CVE-2026-22041 MEDIUM
Logging Redactor <0.0.6 - Type Error
CVSS 5.3
CVE-2026-21692 HIGH
iccdev < 2.3.1.2 - Type Confusion in ToXmlCurve()
CVSS 8.8
CVE-2026-21673 HIGH
iccDEV < 2.3.1.1 - Integer Overflow in CIccXmlArrayType::ParseTextCountNum()
CVSS 7.8
CVE-2025-51678 HIGH
PicoRV32 commit 87c89a - Memory Corruption via PCPI Instruction and Address Mismatch
CVSS 7.5
CVE-2025-40541 CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Insecure Direct Object Reference
CVSS 9.1
CVE-2025-40540 CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Remote Code Execution via Type Confusion
CVSS 9.1
CVE-2025-40539 CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Remote Code Execution via Type Confusion
CVSS 9.1
CVE-2025-71002 MEDIUM
OneFlow v0.9.0 - Denial of Service via Floating-Point Exception in flow.column_stack
CVSS 6.5
Details
Vulnerabilities 273