目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-807 在安全决策中依赖未经信任的输入 类漏洞列表 86

CWE-807 在安全决策中依赖未经信任的输入 类弱点 86 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-807 属于依赖不可信输入进行安全决策的漏洞。攻击者通过篡改 Cookie、环境变量或隐藏表单字段等输入,绕过产品依赖这些值建立的保护机制。开发者需摒弃对客户端数据的盲目信任,不应假设此类输入不可修改。在关键安全逻辑中,必须对输入进行严格验证、完整性校验及服务端重新计算,确保决策依据不被恶意操纵,从而防止安全控制失效。

MITRE CWE 官方描述
CWE:CWE-807 在安全决策中依赖不可信输入 英文:产品使用了一种保护机制,该机制依赖于某个输入的存在性或值,但该输入可以被不可信的行为者以绕过该保护机制的方式进行修改。 开发人员可能假设诸如 cookies、环境变量和隐藏表单字段等输入无法被修改。然而,攻击者可以使用定制的客户端或其他攻击手段来更改这些输入。这种更改可能不会被检测到。当基于这些输入的值进行身份验证(authentication)和授权(authorization)等安全决策时,攻击者可以绕过软件的安全性。如果没有足够的加密(encryption)、完整性检查(integrity checking)或其他机制,任何源自外部的输入都不可信。
常见影响 (1)
Confidentiality, Access Control, Availability, Other Bypass Protection Mechanism, Gain Privileges or Assume Identity, Varies by Context
Attackers can bypass the security decision to access whatever is being protected. The consequences will depend on the associated functionality, but they can range from granting additional privileges to untrusted users to bypassing important security checks. Ultimately, this weakness may lead to expo…
缓解措施 (5)
Architecture and Design Store state information and sensitive data on the server side only. Ensure that the system definitively and unambiguously keeps track of its own state and user state and has rules defined for legitimate state transitions. Do not allow any application user to affect state directly in any way other than through legitimate actions leading to state transitions. If information must be stored on the cli…
Architecture and Design Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. With a stateless protocol such as HTTP, use a framework that maintains the state for you. Examples include ASP.NET View State [REF-756] and the OWASP ESAPI Session Management feature [REF-45]. Be careful of language features that provide state support, since …
Architecture and Design For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Operation, Implementation When using PHP, configure the application so that it does not use register_globals. During implementation, develop the application so that it does not rely on this feature, but be wary of implementing a register_globals emulation that is subject to weaknesses such as CWE-95, CWE-621, and similar issues.
Architecture and Design, Implementation Understand all the potential areas where untrusted inputs can enter your software: parameters or arguments, cookies, anything read from the network, environment variables, reverse DNS lookups, query results, request headers, URL components, e-mail, files, filenames, databases, and any external systems that provide data to the application. Remember that such inputs may be obtained indirectly throug…
代码示例 (2)
The following code excerpt reads a value from a browser cookie to determine the role of the user.
Cookie[] cookies = request.getCookies(); for (int i =0; i< cookies.length; i++) { Cookie c = cookies[i]; if (c.getName().equals("role")) { userRole = c.getValue(); } }
Bad · Java
The following code could be for a medical records application. It performs authentication by checking if a cookie has been set.
$auth = $_COOKIES['authenticated']; if (! $auth) { if (AuthenticateUser($_POST['user'], $_POST['password']) == "success") { // save the cookie to send out in future responses setcookie("authenticated", "1", time()+60*60*2); } else { ShowLoginScreen(); die("\n"); } } DisplayMedicalHistory($_POST['patient_ID']);
Bad · PHP
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-104658 hMailServer 安全决策依赖不可信输入漏洞 — hMailServer 7.8 High 2026-10-08
CVE-2026-103923 KaTeX 原型污染绕过信任限制漏洞 — KaTeX 2.1 Low 2026-10-01
CVE-2026-103267 Ghost 6.62.0前版本任意邮箱注册漏洞 — Ghost 4.3 Medium 2026-10-01
CVE-2026-102117 Kiteworks Core 远程代码执行漏洞 — Core 7.2 High 2026-09-30
CVE-2026-101131 DeepSeek-Harness 依赖不可信输入的安全决策漏洞 — deepseek-harness 3.3 Low 2026-09-28
CVE-2026-101079 agentverus-scanner 上下文安全决策依赖不可信输入漏洞 — agentverus-scanner 2.8 Low 2026-09-28
CVE-2026-84474 Ansible AWX view_jobtemplate 权限提升漏洞 — Red Hat Ansible Automation Platform 2.4 for RHEL 8 9.9 Critical 2026-09-23
CVE-2026-56681 9Router公共LLM API身份验证绕过漏洞 — 9router 7.3 High 2026-09-22
CVE-2026-87858 Temporal Server 管理权限劫持漏洞 — Temporal Server 7.2 High 2026-09-21
CVE-2026-81179 SysReptor 主机头注入账户接管漏洞 — sysreptor 8.1 High 2026-09-18
CVE-2026-78427 Admission控制侧车镜像豁免硬编码绕过漏洞 — github.com/neuvector/neuvector 5.3 Medium 2026-09-17
CVE-2026-79701 SP Page Builder Pro 验证码绕过漏洞 — SP Page Builder (Pro) extension for Joomla 6.9 Medium 2026-09-14
CVE-2026-79700 Joomla SP Page Builder Pro 5.1.4-6.9.0 未认证CAPTCHA绕过 — SP Page Builder (Pro) extension for Joomla 6.9 Medium 2026-09-14
CVE-2026-87479 Google Chrome 输入验证错误漏洞 — Chrome - - 2026-09-09
CVE-2026-82533 DeepSeek Harness 输入验证错误漏洞 — DeepSeek Harness 9.6 Critical 2026-09-08
CVE-2026-66768 SAP NetWeaver 输入验证错误漏洞 — SAP NetWeaver (SAP GUI for Java) 9.0 Critical 2026-09-08
CVE-2026-85602 grav-plugin-form 输入验证错误漏洞 — grav-plugin-form 5.3 Medium 2026-09-04
CVE-2026-63041 Apache APISIX 输入验证错误漏洞 — Apache APISIX 5.3 Medium 2026-08-26
CVE-2026-53789 RsyncProject Rsync 输入验证错误漏洞 — rsync 6.5 Medium 2026-08-13
CVE-2026-64934 Quanovate Mira Firmware 输入验证错误漏洞 — Mira Firmware 4.3 Medium 2026-08-11
CVE-2026-18705 MongoDB Server 输入验证错误漏洞 — MongoDB Server 6.5 Medium 2026-08-11
CVE-2026-58239 SAP Approuter 输入验证错误漏洞 — SAP Business AI Platform (Approuter) 3.7 Low 2026-08-11
CVE-2026-9077 IBM Langflow OSS 输入验证错误漏洞 — Langflow OSS 8.5 High 2026-08-05
CVE-2026-64827 Telenia Software TVox 输入验证错误漏洞 — TVox 9.8 Critical 2026-08-03
CVE-2026-13059 MongoDB Server 输入验证错误漏洞 — MongoDB Server 8.1 High 2026-07-22
CVE-2026-16093 Keycloak 输入验证错误漏洞 — Red Hat build of Keycloak 26.6 5.4 Medium 2026-07-17
CVE-2026-53860 OpenClaw 输入验证错误漏洞 — OpenClaw 4.2 Medium 2026-06-16
CVE-2026-12058 Vivo PcSuite 输入验证错误漏洞 — PcSuite - - 2026-06-12
CVE-2026-6213 Remote Spark SparkView 安全漏洞 — SparkView 8.4AI High AI 2026-05-08
CVE-2026-39807 Bandit 安全漏洞 — bandit 7.5 - 2026-05-01

CWE-807(在安全决策中依赖未经信任的输入) 是常见的弱点类别,本平台收录该类弱点关联的 86 条 CVE 漏洞。