CWE-755

Medium likelihood

Improper Handling of Exceptional Conditions

Parent: CWE-703 - Improper Check or Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

582 vulnerabilities with CWE-755
CVE-2026-59952 MEDIUM
Valibot: record() issue paths can make flatten() throw for inherited Object property names
CVE-2026-42792 MEDIUM
epmd permanent DoS via EMFILE on accept(2) in erts
CVE-2026-48036 HIGH
Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
CVE-2026-16730 MEDIUM
Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup
CVSS 5.5
CVE-2026-62994 LOW
CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
CVSS 3.7
CVE-2026-59162 HIGH
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
CVSS 7.5
CVE-2026-54775 MEDIUM
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVSS 6.5
CVE-2026-59927 MEDIUM
Mistune < 3.3.0 Include Directive - Uncontrolled Recursion Denial of Service
CVSS 5.3
CVE-2026-55577 MEDIUM
ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder
CVSS 5.9
CVE-2026-44505 MEDIUM
Nimiq network-libp2p: Untrusted peer can wedge DHT
CVSS 5.3
CVE-2026-40371 HIGH
Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
CVSS 8.8
CVE-2026-49235 HIGH
Routinator crashes on specifically crafted RRDP XML files
CVSS 7.5
CVE-2026-49232 HIGH
Routinator exits when accepting an incoming HTTP or RTR connection fails
CVE-2026-9516 HIGH
Cpanel::JSON::XS < 4.41 - UTF-8 BOM Decode Denial of Service
CVSS 7.5
CVE-2026-48524 LOW
PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
CVSS 3.7
CVE-2026-44325 HIGH
free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflect.Set on incompatible types)
CVSS 7.5
CVE-2026-44319 HIGH
free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
CVSS 7.5
CVE-2026-44902 HIGH
opentelemetry-js: Prometheus exporter process crash via malformed HTTP request
CVSS 7.5
CVE-2026-48961 HIGH
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID
CVSS 7.3
CVE-2026-42545 MEDIUM
Granian: DoS via WSGI response header panic
CVSS 5.9
CVE-2026-8162 HIGH
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
CVSS 7.5
CVE-2026-34065 HIGH
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
CVSS 7.5
CVE-2026-23666 HIGH
Microsoft .NET Framework - Input Validation Denial of Service
CVSS 7.5
CVE-2026-40074 HIGH
SvelteKit's invalidated redirect in handle hook causes Denial-of-Service
CVSS 7.5
CVE-2026-30798 HIGH
RustDesk Client <=1.4.5 - Protocol Manipulation
CVSS 7.5
Details
Vulnerabilities 582
Exploit Likelihood Medium