Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-1289 — Vulnerability Class 26

26 vulnerabilities classified as CWE-1289. AI Chinese analysis included.

CWE-1289 represents a critical input validation weakness where software fails to properly verify that an input value is equivalent to a potentially unsafe resource identifier or reference. This flaw typically allows attackers to bypass security controls by crafting inputs that appear benign at the application layer but trigger dangerous behavior when processed by downstream components or lower-level systems. By exploiting discrepancies in how equivalence is interpreted across different processing stages, adversaries can execute unauthorized actions or access restricted resources. To mitigate this risk, developers must implement rigorous, consistent validation logic that explicitly checks for unsafe equivalence at every processing layer. Utilizing standardized libraries for reference comparison and ensuring that all downstream components adhere to the same strict validation rules prevents attackers from leveraging these semantic gaps to compromise system integrity.

MITRE CWE Description
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value. Attackers can sometimes bypass input validation schemes by finding inputs that appear to be safe, but will be dangerous when processed at a lower layer or by a downstream component. For example, a simple XSS protection mechanism might try to validate that an input has no "<script>" tags using case-sensitive matching, but since HTML is case-insensitive when processed by web browsers, an attacker could inject "<ScrIpT>" and trigger XSS.
Common Consequences (1)
Other Varies by Context
Mitigations (1)
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
Effectiveness: High
CVE ID Title CVSS Severity Published
CVE-2026-100255 JetBrains TeamCity多版本管理员账户接管漏洞 — TeamCity 8.1 High 2026-09-30
CVE-2026-97196 WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability — GiveWP 9.1 Critical 2026-09-30
CVE-2026-101015 Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equivalence in input — OpenDMARC 7.3 High 2026-09-28
CVE-2026-100837 Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching — contrast 3.7 Low 2026-09-27
CVE-2026-86831 Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS — aws-network-policy-agent 8.7 High 2026-09-16
CVE-2026-88255 mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot — mpp 6.3 Medium 2026-09-16
CVE-2026-76977 Clickjacking vulnerability in SAPUI5(Frame Options Allowlist) — SAPUI5(Frame Options Allowlist) 4.3 Medium 2026-09-08
CVE-2026-19953 URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep - - 2026-08-31
CVE-2026-60074 Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check - - 2026-07-30
CVE-2026-46644 symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence — polyfill - - 2026-07-14
CVE-2026-50090 Aqara OAuth redirect_uri validation bypass — Cloud OAuth Authorization Endpoint 9.3 Critical 2026-06-12
CVE-2026-49942 Net::CIDR::Set versions through 0.20 for Perl did not validate network masks — Net::CIDR::Set - - 2026-06-04
CVE-2026-49940 Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks — Net::CIDR::Set - - 2026-06-04
CVE-2026-45191 Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass — Net::CIDR::Lite 9.1 - 2026-05-10
CVE-2026-45190 Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass — Net::CIDR::Lite 7.5 - 2026-05-10
CVE-2026-39972 Mercure has a Topic Selector Cache Key Collision — mercure 7.6AI High AI 2026-04-09
CVE-2026-34080 xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception — xdg-dbus-proxy 5.3AI Medium AI 2026-04-07
CVE-2026-22569 Incorrect startup configuration in ZCC — Zscaler Client Connector 5.4 Medium 2026-03-31
CVE-2026-33496 Ory Oathkeeper has an authentication bypass by cache key confusion — oathkeeper 8.1 High 2026-03-26
CVE-2026-3563 Devolutions PowerShell Universal 安全漏洞 — PowerShell Universal 7.1AI High AI 2026-03-17
CVE-2026-27610 Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions — parse-dashboard 5.3AI Medium AI 2026-02-25
CVE-2026-1094 Improper Validation of Unsafe Equivalence in Input in GitLab — GitLab 4.6 Medium 2026-02-11
CVE-2024-12224 idna accepts Punycode labels that do not produce any non-ASCII when decoded — rust-url 5.3AI Medium AI 2025-05-30
CVE-2024-8372 AngularJS improper sanitization in 'srcset' attribute — AngularJS 4.8 Medium 2024-09-09
CVE-2024-45308 MySQL & free URL mode allows to hide existing notes in hedgedoc — hedgedoc 6.5 Medium 2024-09-02
CVE-2022-0675 Puppet Firewall Module May Leave Unmanaged Rules — Firewall Module 5.6 Medium 2022-03-02

Vulnerabilities classified as CWE-1289 represent 26 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.