目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-184 不完整的黑名单 类漏洞列表 169

CWE-184 不完整的黑名单 类弱点 169 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-184属于输入验证缺陷,指软件依赖黑名单机制过滤非法输入,但列表存在遗漏。攻击者常利用此漏洞,通过构造未被黑名单覆盖的恶意输入绕过安全限制,从而执行未授权操作或注入攻击。开发者应避免单纯依赖黑名单,转而采用白名单机制严格限定合法输入,或对所有输入进行标准化处理与深度校验,确保防御逻辑的完整性与健壮性。

MITRE CWE 官方描述
CWE:CWE-184 未完全列出禁止输入 英文:产品实现了一种保护机制,该机制依赖于一个输入(或输入属性)列表,这些输入(或属性)因违反策略而被禁止,或需要采取其他措施以在进一步处理之前进行中和,但该列表不完整。
常见影响 (1)
Access Control Bypass Protection Mechanism
Attackers may be able to find other malicious inputs that were not expected by the developer, allowing them to bypass the intended protection mechanism.
缓解措施 (1)
Implementation Do not rely exclusively on detecting disallowed inputs. There are too many variants to encode a character, especially when different environments are used, so there is a high likelihood of missing some variants. Only use detection of disallowed inputs as a mechanism for detecting suspicious activity. Ensure that you are using other protection mechanisms that only identify "good" input - such as …
代码示例 (2)
The following code attempts to stop XSS attacks by removing all occurences of "script" in an input string.
public String removeScriptTags(String input, String mask) { return input.replaceAll("script", mask); }
Bad · Java
This example takes user input, passes it through an encoding scheme, then lists the contents of the user's home directory based on the user name.
sub GetUntrustedInput { return($ARGV[0]); } sub encode { my($str) = @_; $str =~ s/\&/\&amp;/gs; $str =~ s/\"/\&quot;/gs; $str =~ s/\'/\&apos;/gs; $str =~ s/\</\&lt;/gs; $str =~ s/\>/\&gt;/gs; return($str); } sub doit { my $uname = encode(GetUntrustedInput("username")); print "<b>Welcome, $uname!</b><p>\n"; system("cd /home/$uname; /bin/ls -l"); }
Bad · Perl
' pwd
Attack
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-107322 AWS 数据库插件远程命令注入漏洞 — databases-on-aws 7.8 High 2026-10-08
CVE-2026-106445 Handlebars 绕过自身属性检查导致 JavaScript 注入漏洞 — handlebars.js 9.2 Critical 2026-10-06
CVE-2026-106442 Hydra 实例化目标黑名单绕过导致远程代码执行漏洞 — hydra 7.8 High 2026-10-06
CVE-2026-106218 TeamCity <2026.1.3 Kotlin DSL沙箱逃逸致RCE — TeamCity 8.8 High 2026-10-06
CVE-2026-105648 Ghost: IPv6过渡地址绕过私有IP过滤漏洞 — Ghost 4.0 Medium 2026-10-05
CVE-2026-103687 dom-sanitizer SVG 过滤黑名单不完整漏洞 — dom-sanitizer 7.3 High 2026-10-01
CVE-2026-101884 OpenClaw Windows Node 2026.7.1前远程代码执行漏洞 — OpenClaw Windows Node 7.5 High 2026-09-30
CVE-2026-101882 OpenClaw Windows Node 2026.7.1前远程代码执行漏洞 — OpenClaw Windows Node 8.8 High 2026-09-30
CVE-2026-100253 TeamCity多版本Kotlin DSL沙箱逃逸致代码执行 — TeamCity 8.8 High 2026-09-30
CVE-2026-55096 _validate_url_security DNS解析漏洞 — fast-mcp-telegram 7.1 High 2026-09-28
CVE-2026-61788 bytebase/dbhub 只读模式未阻止数据库写入 — dbhub 7.4 High 2026-09-24
CVE-2026-97149 OpenStack Swift 2.38.2前TempURL头注入漏洞 — Swift 5.3 Medium 2026-09-24
CVE-2026-84714 Automation Controller Jinja模板注入漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 7.1 High 2026-09-23
CVE-2026-84706 Ansible Automation Controller 凭据类型环境变量注入器绕过漏洞 — Red Hat Ansible Automation Platform 2.5 for RHEL 8 7.6 High 2026-09-23
CVE-2026-75884 Awx OpenShift命名空间权限提升漏洞 — Red Hat Ansible Automation Platform 2.4 for RHEL 8 9.1 Critical 2026-09-23
CVE-2026-61851 Chartbrew AI runQuery只读关键字黑名单不完整漏洞 — chartbrew 6.5 Medium 2026-09-21
CVE-2026-93598 ArcadeDB 26.9.1 前类路径凭证泄露漏洞 — arcadedb 7.1 High 2026-09-18
CVE-2026-11918 IBM ContextForge MCP Gateway 安全过滤器绕过 — ContextForge MCP Gateway 5.4 Medium 2026-09-15
CVE-2026-57138 Mervin Praison PraisonAI 输入验证错误漏洞 — PraisonAI 9.9 Critical 2026-09-15
CVE-2026-90808 HKUDS nanobot 命令执行黑名单不完整 — nanobot 6.3 Medium 2026-09-14
CVE-2026-87985 Mistral AI Mistral Vibe 输入验证错误漏洞 — mistral-vibe 10.0 Critical 2026-09-11
CVE-2026-85788 Amazon Open source MCP servers for AWS 输入验证错误漏洞 — AWS Labs MySQL MCP Server 5.5 Medium 2026-09-09
CVE-2026-86199 PMMP PocketMine-MP 输入验证错误漏洞 — PocketMine-MP 7.5 High 2026-09-09
CVE-2026-79696 Google Agent Development Kit 输入验证错误漏洞 — Agent Development Kit (ADK) for Python 10.0 Critical 2026-09-09
CVE-2026-82536 RooCodeInc Roo Code 输入验证错误漏洞 — Roo-Code 8.8 High 2026-09-08
CVE-2026-69624 Microsoft Active Directory Certificate Services 输入验证错误漏洞 — Windows 10 Version 1607 6.5 Medium 2026-09-08
CVE-2026-70334 Microsoft Visual Studio Code 输入验证错误漏洞 — Visual Studio Code 7.8 High 2026-09-08
CVE-2026-33197 AMI AptioV 输入验证错误漏洞 — AptioV 8.7 High 2026-09-08
CVE-2026-85787 Amazon awslabs postgres-mcp-server 输入验证错误漏洞 — postgres-mcp-server 6.5 Medium 2026-09-04
CVE-2026-77124 Sonatype Nexus Repository Manager 输入验证错误漏洞 — Nexus Repository 3 7.5 High 2026-09-02

CWE-184(不完整的黑名单) 是常见的弱点类别,本平台收录该类弱点关联的 169 条 CVE 漏洞。