Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-348 (使用不可信的源) — Vulnerability Class 69

69 vulnerabilities classified as CWE-348 (使用不可信的源). AI Chinese analysis included.

CWE-348 represents a trust relationship management weakness where software incorrectly relies on a data source with insufficient verification or security controls. This flaw typically arises when applications accept input from external entities, such as user-supplied fields or unvalidated network packets, instead of prioritizing internal, authenticated sources. Attackers exploit this by injecting malicious payloads or manipulating data through the less trusted channel, bypassing intended security checks and potentially leading to injection attacks, privilege escalation, or data corruption. To mitigate this risk, developers must rigorously validate all external inputs against strict allowlists and implement robust authentication mechanisms. By consistently prioritizing verified, internal data sources and applying defense-in-depth strategies, engineers can ensure that critical operations rely only on trustworthy information, thereby neutralizing the threat of compromised data integrity.

MITRE CWE Description
The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.
Common Consequences (1)
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity
An attacker could utilize the untrusted data source to bypass protection mechanisms and gain access to sensitive data.
Examples (1)
This code attempts to limit the access of a page to certain IP Addresses. It checks the 'HTTP_X_FORWARDED_FOR' header in case an authorized user is sending the request through a proxy.
$requestingIP = '0.0.0.0'; if (array_key_exists('HTTP_X_FORWARDED_FOR', $_SERVER)) { $requestingIP = $_SERVER['HTTP_X_FORWARDED_FOR']; else{ $requestingIP = $_SERVER['REMOTE_ADDR']; } if(in_array($requestingIP,$ipAllowlist)){ generatePage(); return; } else{ echo "You are not authorized to view this page"; return; }
Bad · PHP
$requestingIP = '0.0.0.0'; if (array_key_exists('HTTP_X_FORWARDED_FOR', $_SERVER)) { echo "This application cannot be accessed through a proxy."; return; else{ $requestingIP = $_SERVER['REMOTE_ADDR']; } ...
Good · PHP
CVE ID Title CVSS Severity Published
CVE-2026-102630 UnoPim 2.0.0 before 2.0.1 and 2.1.0 before 2.1.1 Cache Poisoning via X-Forwarded-Host — unopim 4.7 Medium 2026-09-29
CVE-2026-101277 Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less trusted source — OpenDKIM 6.5 Medium 2026-09-28
CVE-2026-100653 vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation — vllm 6.5 Medium 2026-09-26
CVE-2026-97404 OpenStack Zaqar < 22.0.2 WSGI认证绕过漏洞 — Zaqar 9.2 Critical 2026-09-24
CVE-2026-92530 Use of Less Trusted Source in GitLab — GitLab 4.3 Medium 2026-09-23
CVE-2026-84718 Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust — Red Hat Ansible Automation Platform 2.5 for RHEL 8 4.3 Medium 2026-09-23
CVE-2026-61589 djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path — djust 6.3 Medium 2026-09-16
CVE-2026-90679 Forgejo 信任管理问题漏洞 — Forgejo 4.3 Medium 2026-09-13
CVE-2026-16272 Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module — PayTR Virtual Pos iFrame API (v9x) WHMCS Module 9.1 Critical 2026-09-09
CVE-2026-16732 fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count — fastify 6.1 Medium 2026-08-18
CVE-2026-25552 Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header — Ghost-CLI 3.7 Low 2026-07-31
CVE-2026-63220 CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() — CodeIgniter4 4.8 Medium 2026-07-31
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL — Unbound - - 2026-07-22
CVE-2026-63770 Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass — glance 7.5 High 2026-07-20
CVE-2026-64619 FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers — FileCodeBox 7.5 High 2026-07-20
CVE-2026-9561 Eclipse kura 输入验证错误漏洞 — Eclipse Kura - - 2026-07-14
CVE-2026-58122 Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing — hermes-webui 9.1 Critical 2026-07-09
CVE-2026-59897 Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication — hono 4.8 Medium 2026-07-08
CVE-2026-59999 OpenBSD OpenSSH 信任管理问题漏洞 — OpenSSH 5.9 Medium 2026-07-08
CVE-2026-46466 Dell PowerProtect Data Domain 信任管理问题漏洞 — PowerProtect Data Domain 2.7 Low 2026-07-03
CVE-2026-57942 LibreTranslate - IP Spoofing via X-Forwarded-For Header — LibreTranslate 5.3 Medium 2026-06-29
CVE-2026-54289 Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest — hono 4.8 Medium 2026-06-22
CVE-2026-12249 Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment 8.3 Critical 2026-06-22
CVE-2026-48772 ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL — proxysql 10.0 Critical 2026-06-19
CVE-2026-44046 Apache APISIX: wolf-rbac plugin Identity Spoofing — Apache APISIX - - 2026-06-19
CVE-2020-37248 OfflineIMAP 安全漏洞 — OfflineIMAP 6.5 Medium 2026-06-08
CVE-2026-43634 HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header — hestiacp 7.5 High 2026-05-19
CVE-2026-40226 systemd 安全漏洞 — systemd 6.4 Medium 2026-04-10
CVE-2026-35391 Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery — webmail 9.1AI Critical AI 2026-04-06
CVE-2026-35507 shynet 安全漏洞 — Shynet 6.4 Medium 2026-04-03

Vulnerabilities classified as CWE-348 (使用不可信的源) represent 69 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.