Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-130 (长度参数不一致性处理不恰当) — Vulnerability Class 90

90 vulnerabilities classified as CWE-130 (长度参数不一致性处理不恰当). AI Chinese analysis included.

CWE-130 represents a critical logic flaw where software fails to validate that a declared length parameter matches the actual size of the associated data buffer. This inconsistency typically arises during the parsing of formatted messages or structured inputs, allowing attackers to manipulate length fields to deceive the application. By exploiting this discrepancy, adversaries can trigger buffer overflows, memory corruption, or unexpected control flow alterations, potentially leading to remote code execution or denial of service. To mitigate this vulnerability, developers must implement rigorous input validation that strictly verifies the integrity of length fields against actual data sizes before processing. Employing safe string handling libraries, enforcing strict type checking, and utilizing bounds-checking mechanisms ensures that the application correctly interprets data structures, thereby preventing attackers from leveraging length mismatches to compromise system stability or security.

MITRE CWE Description
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data. If an attacker can manipulate the length parameter associated with an input such that it is inconsistent with the actual length of the input, this can be leveraged to cause the target application to behave in unexpected, and possibly, malicious ways. One of the possible motives for doing so is to pass in arbitrarily large input to the application. Another possible motivation is the modification of application state by including invalid data for subsequent properties of the application. Such weaknesses commonly lead to attacks such as buffer overflows and execution of arbitrary code.
Common Consequences (1)
Confidentiality, Integrity Read Memory, Modify Memory, Varies by Context
Mitigations (3)
Implementation When processing structured incoming data containing a size field followed by raw data, ensure that you identify and resolve any inconsistencies between the size field and the actual size of the data.
Implementation Do not let the user control the size of the buffer.
Implementation Validate that the length of the user-supplied data is consistent with the buffer size.
Examples (1)
In the following C/C++ example the method processMessageFromSocket() will get a message from a socket, placed into a buffer, and will parse the contents of the buffer into a structure that contains the message length and the message body. A for loop is used to copy the message body into a local character string which will be passed to another method for processing.
int processMessageFromSocket(int socket) { int success; char buffer[BUFFER_SIZE]; char message[MESSAGE_SIZE]; // get message from socket and store into buffer //Ignoring possibliity that buffer > BUFFER_SIZE if (getMessage(socket, buffer, BUFFER_SIZE) > 0) { // place contents of the buffer into message structure ExMessage *msg = recastBuffer(buffer); // copy message body into string for processing int index; for (index = 0; index < msg->msgLength; index++) { message[index] = msg->msgBody[index]; } message[index] = '\0'; // process message success = processMessage(message); } return success; }
Bad · C
CVE ID Title CVSS Severity Published
CVE-2026-85494 Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Framed transport and binary protocol size read buffers from a peer-declared length without a limit (multi-language) — Apache Thrift 8.7 High 2026-10-02
CVE-2026-87022 Apache Tomcat: WebSocket message smuggling with per-message-deflate — Apache Tomcat - - 2026-09-23
CVE-2026-77619 Vector: Unauthenticated denial of service in the `logstash` source via unbounded memory allocation. — vector 8.7 High 2026-09-22
CVE-2023-5778 Missing Length Check — Freelance Controller DCP 7.5 High 2026-09-18
CVE-2026-73455 Security Advisory 0173 — EOS 7.5 High 2026-09-16
CVE-2026-90678 HAProxy 输入验证错误漏洞 — HAProxy 7.5 High 2026-09-13
CVE-2026-15418 CP210x Memory Leakage — silabser.sys driver 2.4 Low 2026-09-10
CVE-2026-5706 Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements — BT Mesh SDK 8.9 High 2026-08-27
CVE-2026-81575 Missing Sanity Checks for Buffer Lengths — codemeter-runtime 7.5 High 2026-08-27
CVE-2026-58097 ppp(8): missing length validation in mp_SetEnddisc() — FreeBSD - - 2026-08-26
CVE-2026-58096 ppp(8): missing length validation in LcpDecodeConfig() — FreeBSD - - 2026-08-26
CVE-2026-14587 Unathenticated connection can hold Bolt channel open — Enterprise Edition 5.5 Medium 2026-08-05
CVE-2026-67292 FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure — FreeRDP 6.5 Medium 2026-08-01
CVE-2026-26081 HAProxy 输入验证错误漏洞 — HAProxy 4.8 Medium 2026-07-20
CVE-2026-54466 websocket-driver: Message corruption via abuse of protocol length headers — websocket-driver-node - - 2026-07-17
CVE-2026-48487 Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet — python-zeroconf - - 2026-07-17
CVE-2026-60060 TeraTerm Project TTSSH2 输入验证错误漏洞 — TTSSH2 - - 2026-07-17
CVE-2026-47692 Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream — envoy 4.8 Medium 2026-06-26
CVE-2026-6432 Improper bounds validation in EmberZNet SDK — SiSDK - - 2026-06-25
CVE-2026-5766 Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass — Django 5.3 Medium 2026-05-05
CVE-2026-33846 Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly — Red Hat Enterprise Linux 10 7.5 High 2026-05-04
CVE-2026-3868 Moxa EDR-8010 Series和Moxa EDR-G9010 Series 安全漏洞 — EDR-8010 Series 7.5AI High AI 2026-04-27
CVE-2026-5265 Ovn: ovn: heap over-read in icmp error response generation — Fast Datapath for Red Hat Enterprise Linux 10 6.5 Medium 2026-04-24
CVE-2026-5367 Ovn: ovn: information disclosure via crafted dhcpv6 packets — Fast Datapath for Red Hat Enterprise Linux 10 8.6 High 2026-04-24
CVE-2026-41035 Rsync 安全漏洞 — rsync 7.4 High 2026-04-16
CVE-2026-33555 HAProxy 安全漏洞 — HAProxy 4.0 Medium 2026-04-13
CVE-2026-40199 Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass — Net::CIDR::Lite 7.5 - 2026-04-10
CVE-2026-34831 Rack: Content-Length mismatch in Rack::Files error responses — rack 4.8 Medium 2026-04-02
CVE-2026-25572 Siemens SICAM SIAPP SDK 安全漏洞 — SICAM SIAPP SDK 5.1 Medium 2026-03-10
CVE-2026-25571 Siemens SICAM SIAPP SDK 安全漏洞 — SICAM SIAPP SDK 5.1 Medium 2026-03-10

Vulnerabilities classified as CWE-130 (长度参数不一致性处理不恰当) represent 90 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.