CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

Parent: CWE-704 - Incorrect Type Conversion or Cast

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

847 vulnerabilities with CWE-843
CVE-2026-33937 CRITICAL
Handlebars.js has JavaScript Injection via AST Type Confusion
CVSS 9.8
CVE-2026-28822 MEDIUM
iOS and iPadOS < 26.4 - Type Confusion
CVSS 6.2
CVE-2026-4702 CRITICAL
JIT miscompilation in the JavaScript Engine component
CVSS 9.8
CVE-2026-4698 CRITICAL
JIT miscompilation in the JavaScript Engine: JIT component
CVSS 9.8
CVE-2026-32701 HIGH
Qwik has array method pollution in FormData processing, allowing type confusion and DoS
CVSS 7.5
CVE-2026-33055 HIGH
tar-rs incorrectly ignores PAX size headers if header size is nonzero
CVSS 8.1
CVE-2026-4457 HIGH
Google Chrome <146.0.7680.153 - Memory Corruption
CVSS 8.8
CVE-2026-31968 HIGH
HTSlib CRAM decoder vulnerable to buffer overflow
CVSS 8.1
CVE-2026-29079 HIGH
Lexbor < 2.7.0 - Type Confusion in HTML Fragment Parser
CVSS 7.5
CVE-2026-26110 HIGH
Microsoft Office - Memory Corruption
CVSS 8.4
CVE-2026-2796 CRITICAL
Firefox < 148.0 - Type Confusion in JavaScript WebAssembly JIT
CVSS 9.8
CVE-2026-2783 HIGH
Firefox <148 & ESR <140.8 - Info Disclosure
CVSS 7.5
CVE-2026-21519 HIGH KEV
Windows 10/11 Privilege Escalation via Desktop Window Manager Type Confusion
CVSS 7.8
CVE-2026-21330 HIGH
Adobe After Effects < 25.6.4 - Remote Code Execution via Type Confusion
CVSS 7.8
CVE-2026-24914 MEDIUM
HarmonyOS - Use-After-Free in Camera Module
CVSS 4.0
CVE-2026-25537 HIGH
jsonwebtoken < 10.3.0 - Authentication Bypass via Claim Type Confusion
CVSS 7.5
CVE-2026-1862 HIGH
Google Chrome <144.0.7559.132 - Heap Corruption
CVSS 8.8
CVE-2026-25503 HIGH
iccdev < 2.3.1.2 - Denial of Service via Malformed ICC Profile
CVSS 7.1
CVE-2026-24874 CRITICAL
themrdemonized xray-monolith <2025.12.30 - Type Confusion
CVSS 9.1
CVE-2026-20860 HIGH
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
CVE-2026-20811 HIGH
Windows Win32K - ICOMP - Privilege Escalation
CVSS 7.8
CVE-2026-22028 MEDIUM
Preact 10.26.5-10.26.10 - HTML Injection via JSON Payload Type Confusion
CVSS 6.1
CVE-2026-22046 HIGH
iccdev < 2.3.1.2 - Heap-Based Buffer Overflow in CIccProfileXml::ParseBasic()
CVSS 8.8
CVE-2026-21693 HIGH
iccDEV < 2.3.1.2 - Type Confusion in CIccSegmentedCurveXml::ToXml()
CVSS 8.8
CVE-2026-21692 HIGH
iccdev < 2.3.1.2 - Type Confusion in ToXmlCurve()
CVSS 8.8
Details
Vulnerabilities 847