CWE-129 对数组索引的验证不恰当 类弱点 187 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-129 属于数组索引验证不当漏洞,指程序使用不可信输入计算数组索引时,未进行有效校验或校验逻辑错误,导致索引越界。攻击者通常通过构造恶意输入,使索引指向非法内存位置,从而引发缓冲区溢出、数据篡改或拒绝服务攻击。开发者应严格验证输入数据的范围,确保其始终处于数组合法边界内,并采用安全的边界检查机制,从源头阻断越界访问风险。
public String getValue(int index) { return array[index]; }private void buildList ( int untrustedListSize ){ if ( 0 > untrustedListSize ){ die("Negative value supplied for list size, die evil hacker!"); } Widget[] list = new Widget [ untrustedListSize ]; list[0] = new Widget(); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-25276 | 安全处理器数组索引验证不当漏洞 — Snapdragon | 8.8 | High | 2026-06-01 |
| CVE-2026-45104 | Mapserver 代码问题漏洞 — MapServer | 7.5 | High | 2026-05-27 |
| CVE-2026-44310 | Gitsign 输入验证错误漏洞 — gitsign | 5.4 | Medium | 2026-05-15 |
| CVE-2023-31309 | AMD Radeon 输入验证错误漏洞 — AMD Radeon™ RX 6000 Series Graphics Products | - | - | 2026-05-15 |
| CVE-2026-44222 | vLLM 输入验证错误漏洞 — vllm | 6.5 | Medium | 2026-05-12 |
| CVE-2026-41643 | GoBGP 输入验证错误漏洞 — gobgp | 7.5 | High | 2026-05-07 |
| CVE-2026-40251 | Incus 输入验证错误漏洞 — incus | 6.5AI | MediumAI | 2026-05-06 |
| CVE-2026-40886 | Argo Workflows 输入验证错误漏洞 — argo-workflows | 7.7 | High | 2026-04-23 |
| CVE-2026-6840 | ONE 输入验证错误漏洞 — ONE | 5.5 | Medium | 2026-04-22 |
| CVE-2026-40097 | Smallstep step-ca 输入验证错误漏洞 — certificates | 3.7 | Low | 2026-04-10 |
| CVE-2026-34942 | wasmtime 输入验证错误漏洞 — wasmtime | 7.7AI | HighAI | 2026-04-09 |
| CVE-2026-21413 | Libraw 安全漏洞 — LibRaw | 9.8 | Critical | 2026-04-07 |
| CVE-2026-33762 | go-git 输入验证错误漏洞 — go-git | 2.8 | Low | 2026-03-31 |
| CVE-2026-33281 | Ella Core 输入验证错误漏洞 — core | 6.5 | Medium | 2026-03-23 |
| CVE-2026-33022 | Tekton Pipelines 输入验证错误漏洞 — pipeline | 6.5 | Medium | 2026-03-20 |
| CVE-2026-32937 | free5GC 输入验证错误漏洞 — chf | 6.5 | - | 2026-03-20 |
| CVE-2026-26933 | Elastic Packetbeat 安全漏洞 — Packetbeat | 5.7 | Medium | 2026-03-19 |
| CVE-2026-3083 | GStreamer 输入验证错误漏洞 — GStreamer | 9.8 | - | 2026-03-13 |
| CVE-2026-26932 | Elastic Packetbeat 安全漏洞 — Packetbeat | 5.7 | Medium | 2026-02-26 |
| CVE-2026-25882 | Fiber 安全漏洞 — fiber | 7.5AI | HighAI | 2026-02-24 |
| CVE-2025-69248 | free5GC 输入验证错误漏洞 — amf | 7.5AI | HighAI | 2026-02-23 |
| CVE-2023-20601 | AMD Graphics Driver 安全漏洞 — AMD Radeon™ PRO VII | 5.5AI | MediumAI | 2026-02-12 |
| CVE-2026-2006 | PostgreSQL 安全漏洞 — PostgreSQL | 8.8 | High | 2026-02-12 |
| CVE-2026-25518 | cert-manager 代码问题漏洞 — cert-manager | 5.9 | Medium | 2026-02-04 |
| CVE-2026-25068 | alsa-lib 输入验证错误漏洞 — alsa-lib | 6.5 | - | 2026-01-29 |
| CVE-2026-0529 | Elastic Packetbeat 安全漏洞 — Packetbeat | 6.5 | Medium | 2026-01-14 |
| CVE-2026-0528 | Elastic Metricbeat 安全漏洞 — Metricbeat | 6.5 | Medium | 2026-01-13 |
| CVE-2025-47393 | Qualcomm Chipsets 输入验证错误漏洞 — Snapdragon | 7.8 | High | 2026-01-06 |
| CVE-2025-15271 | FontForge 输入验证错误漏洞 — FontForge | 7.8 | - | 2025-12-31 |
| CVE-2025-15270 | FontForge 输入验证错误漏洞 — FontForge | 7.8 | - | 2025-12-31 |
CWE-129(对数组索引的验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 187 条 CVE 漏洞。