Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-349 (在可信数据中接受外来的不可信数据) — Vulnerability Class 38

38 vulnerabilities classified as CWE-349 (在可信数据中接受外来的不可信数据). AI Chinese analysis included.

CWE-349 represents a critical input validation weakness where software incorrectly processes untrusted data embedded alongside trusted inputs, treating the malicious elements as legitimate. Attackers typically exploit this by injecting harmful payloads, such as SQL commands or script tags, into fields that are otherwise expected to contain safe, verified information. Because the application fails to distinguish between the two data sources, it executes the untrusted content, leading to severe vulnerabilities like injection attacks or data corruption. Developers can prevent this by implementing strict input sanitization and validation routines that isolate and verify each data component independently. By explicitly defining allowed formats and rejecting any unexpected characters or structures, even those hidden within trusted streams, engineers ensure that only verified, safe data influences the application’s logic, thereby maintaining system integrity.

MITRE CWE Description
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
Common Consequences (1)
Access Control, Integrity Bypass Protection Mechanism, Modify Application Data
An attacker could package untrusted data with trusted data to bypass protection mechanisms to gain access to and possibly modify sensitive data.
CVE ID Title CVSS Severity Published
CVE-2026-48100 Payy: agg_agg trailing message slots are unconstrained and allow forged burn messages — payy 8.7 High 2026-09-28
CVE-2026-19033 Unauthenticated IXFR deltas are applied to the live zone before TSIG verification — BIND 9 6.5 Medium 2026-09-16
CVE-2026-78301 Out-of-zone database nodes can become authoritative zone cuts — BIND 9 5.8 Medium 2026-09-16
CVE-2026-15387 Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab — GitLab 4.3 Medium 2026-08-26
CVE-2026-54625 django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) — django-cms 4.8 Medium 2026-08-20
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread — Unbound - - 2026-07-22
CVE-2026-41120 Dell Wyse Management Suite 信任管理问题漏洞 — Wyse Management Suite 9.8 Critical 2026-06-25
CVE-2026-45602 Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability — Windows 10 Version 1607 9.1 Critical 2026-06-09
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section — Unbound - - 2026-05-20
CVE-2026-44572 Next.js: Middleware / Proxy redirects can be cache-poisoned — next.js 3.7 Low 2026-05-13
CVE-2026-32162 Windows COM Elevation of Privilege Vulnerability — Windows 10 Version 1809 8.4 High 2026-04-14
CVE-2026-35641 OpenClaw < 2026.3.24 - Arbitrary Code Execution via .npmrc in Local Plugin/Hook Installation — OpenClaw 7.8 High 2026-04-10
CVE-2026-1642 NGINX vulnerability — NGINX Open Source 5.9 Medium 2026-02-04
CVE-2025-68269 JetBrains IntelliJ IDEA 安全漏洞 — IntelliJ IDEA 5.4 Medium 2025-12-16
CVE-2025-1680 Moxa Ethernet switches 安全漏洞 — TN-4500A Series 6.7AI Medium AI 2025-10-23
CVE-2025-40778 Cache poisoning attacks with unsolicited RRs — BIND 9 8.6 High 2025-10-22
CVE-2025-11411 Possible domain hijacking via promiscuous records in the authority section — Unbound 7.5AI High AI 2025-10-22
CVE-2025-11703 WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning — WP Go Maps (formerly WP Google Maps) 5.3 Medium 2025-10-18
CVE-2025-5994 Cache poisoning via the ECS-enabled Rebirthday Attack — Unbound 5.3 - 2025-07-16
CVE-2025-40776 Birthday Attack against Resolvers supporting ECS — BIND 9 8.6 High 2025-07-16
CVE-2025-48804 Windows BitLocker Security Feature Bypass Vulnerability — Windows 10 Version 1507 6.8 Medium 2025-07-08
CVE-2025-46339 FreshRSS vulnerable to favicon cache poisoning via proxy — FreshRSS 4.3 Medium 2025-06-04
CVE-2025-20255 Cisco Webex Meetings 安全漏洞 — Cisco Webex Meetings 4.3 Medium 2025-05-21
CVE-2025-29842 UrlMon Security Feature Bypass Vulnerability — Windows 10 Version 1507 7.5 High 2025-05-13
CVE-2025-29816 Microsoft Word Security Feature Bypass Vulnerability — Microsoft 365 Apps for Enterprise 7.5 High 2025-04-08
CVE-2025-27415 Nuxt allows DOS via cache poisoning with payload rendering response — nuxt 7.5 High 2025-03-19
CVE-2024-53848 check-jsonschema default caching for remote schemas allows for cache confusion — check-jsonschema 7.1 High 2024-11-29
CVE-2024-52555 JetBrains WebStorm 安全漏洞 — WebStorm 6.3 Medium 2024-11-15
CVE-2024-42483 ESP-NOW Replay Attacks Vulnerability — esp-now 6.5 Medium 2024-09-12
CVE-2024-34083 STARTTLS unencrypted commands injection — aiosmtpd 5.4 Medium 2024-05-18

Vulnerabilities classified as CWE-349 (在可信数据中接受外来的不可信数据) represent 38 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.