Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-134 (使用外部控制的格式字符串) — Vulnerability Class 138

138 vulnerabilities classified as CWE-134 (使用外部控制的格式字符串). AI Chinese analysis included.

CWE-134 represents a critical input validation weakness where software utilizes functions accepting format strings, such as printf, with data originating from an untrusted external source. Attackers typically exploit this vulnerability by injecting malicious format specifiers, like %x or %n, into the input stream. This manipulation allows them to read sensitive memory contents, causing denial of service, or write arbitrary data to memory, potentially leading to remote code execution and full system compromise. To mitigate this risk, developers must strictly avoid passing user-controlled data directly as the format string argument. Instead, they should use literal format strings and pass user input as subsequent arguments. Additionally, implementing rigorous input validation and employing static analysis tools can help detect these dangerous patterns early in the development lifecycle, ensuring that external data is never interpreted as executable code logic.

MITRE CWE Description
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Common Consequences (2)
Confidentiality Read Memory
Format string problems allow for information disclosure which can severely simplify exploitation of the program.
Integrity, Confidentiality, Availability Modify Memory, Execute Unauthorized Code or Commands
Format string problems can result in the execution of arbitrary code, buffer overflows, denial of service, or incorrect data representation.
Mitigations (3)
Requirements Choose a language that is not subject to this flaw.
Implementation Ensure that all format string functions are passed a static string which cannot be controlled by the user, and that the proper number of arguments are always sent to that function as well. If at all possible, use functions that do not support the %n operator in format strings. [REF-116] [REF-117]
Build and Compilation Run compilers and linkers with high warning levels, since they may detect incorrect usage.
Examples (2)
The following program prints a string provided as an argument.
#include <stdio.h> void printWrapper(char *string) { printf(string); } int main(int argc, char **argv) { char buf[5012]; memcpy(buf, argv[1], 5012); printWrapper(argv[1]); return (0); }
Bad · C
The following code copies a command line argument into a buffer using snprintf().
int main(int argc, char **argv){ char buf[128]; ... snprintf(buf,128,argv[1]); }
Bad · C
CVE ID Title CVSS Severity Published
CVE-2026-69395 Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability — Windows 10 Version 1607 6.5 Medium 2026-09-08
CVE-2026-16821 Vulnerabilities in IBM AIX and PowerVM VIOS — AIX 7.0 High 2026-08-28
CVE-2026-81574 Format String Vulnerability in Logger — codemeter-runtime 8.2 High 2026-08-27
CVE-2026-63073 Untrusted Sender DN Used as Format String in CMP Response Validation — OpenSSL - - 2026-08-25
CVE-2026-17136 Vulnerabilities in IBM AIX and PowerVM VIOS — AIX 9.8 Critical 2026-08-20
CVE-2026-68553 Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command — coturn 7.1 High 2026-08-19
CVE-2026-15961 Power System Information Disclosure — PowerVM Hypervisor 5.2 Medium 2026-08-19
CVE-2026-12004 Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access — Security Verify Access 8.7 High 2026-08-12
CVE-2026-67244 A format string vulnerability was found in the Notification OAuth settings of ADM — ADM 8.6 High 2026-07-30
CVE-2026-18188 A format string vulnerability was found in the Rsync Backup on the ADM — ADM 7.1 High 2026-07-30
CVE-2026-18187 A format string vulnerability was found in the Internal Backup on the ADM — ADM 7.1 High 2026-07-30
CVE-2026-18186 A stored format string vulnerability was found in the FTP Backup on the ADM — ADM 7.1 High 2026-07-30
CVE-2026-6390 Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling. — Red Hat Enterprise Linux 10 6.8 Medium 2026-07-23
CVE-2024-58366 SurrealDB before 1.1.1 Format String via Scripting Functions — surrealdb 8.5 High 2026-07-18
CVE-2026-15809 Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env — Red Hat OpenShift Container Platform 4.12 7.8 High 2026-07-15
CVE-2026-15680 Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability — 2K Indoor Wi-Fi Security Camera - - 2026-07-13
CVE-2026-46465 Dell PowerProtect Data Domain 格式化字符串错误漏洞 — PowerProtect Data Domain 5.5 Medium 2026-07-03
CVE-2026-57877 GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr) — GV-LPCLPC2011/2211 8.6 High 2026-06-26
CVE-2026-10828 Moxa NPort W2150A-W4/W2250A-W4 Series 格式化字符串错误漏洞 — NPort W2150A-W4/W2250A-W4 Series - - 2026-06-16
CVE-2026-12174 D-Link DCS-935L HTTP rhea snprintf format string — DCS-935L 8.8 High 2026-06-13
CVE-2026-6250 Authenticated Format String Injection on TP-Link Tapo C110 — Tapo C110 v2 - - 2026-06-11
CVE-2026-6242 Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C520WS — Tapo C520WS v2 - - 2026-06-05
CVE-2026-6241 Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WS — Tapo C520WS v2 - - 2026-06-05
CVE-2026-50211 Exposed Factory Testing App Boundaries — Connect M6E 5G Portable WiFi Router - - 2026-06-04
CVE-2026-7835 Format string argument mismatch — Netatalk 3.1 Low 2026-05-21
CVE-2026-6474 PostgreSQL timeofday() can disclose portions of server memory — PostgreSQL 4.3 Medium 2026-05-14
CVE-2026-44407 Remote Denial of Service Vulnerability Exists in ZTE Cloud PC Client uSmartview — ZXCLOUD iRAI 4.7 Medium 2026-05-07
CVE-2026-6539 Notepad++ 8.9.3 Format String Injection via nativeLang.xml — Notepad++ 4.4 Medium 2026-04-30
CVE-2026-6843 Nano: nano: format string vulnerability leads to denial of service — Red Hat Enterprise Linux 10 5.5 Medium 2026-04-22
CVE-2026-3509 CODESYS Control Audit Log Format String DoS — CODESYS Control RTE (SL) 7.5 High 2026-03-24

Vulnerabilities classified as CWE-134 (使用外部控制的格式字符串) represent 138 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.