Skip to content
Threat Feed

Tag

Input-Validation

14 briefs RSS
high advisory

Denial of Service Vulnerability in Netty StompSubframeDecoder

A memory leak vulnerability in the Netty StompSubframeDecoder component (CVE-2026-93494) allows remote attackers to cause a Denial of Service by sending malformed STOMP frames.

Netty +1 denial-of-service vulnerability cve-2026-93565 rtsp input-validation
1t 1c
critical advisory

free5GC NRF NF Registration Poisoning via Input Validation Failure

The free5GC Network Repository Function (NRF) fails to validate NF registration requests against 3GPP TS 29.510 standards, allowing unauthenticated attackers to inject fraudulent network function profiles into the 5G core service mesh.

free5GC 5g-core nrf cve-2026-55068 input-validation
1r 2t 1c
high advisory

Authenticated Remote Code Execution in qwed via Unsafe SymPy Parsing

The qwed package (version 5.1.1) fails to sanitize input in math verification endpoints, allowing authenticated attackers to achieve remote code execution via unsafe SymPy expression evaluation.

qwed remote-code-execution input-validation python
1r 1t
high advisory

Path Traversal in GitPython via Malicious Submodule Names

GitPython fails to validate submodule names defined in .gitmodules files, allowing attackers to perform path traversal and create arbitrary Git repositories outside the intended working tree during submodule initialization.

GitPython +1 remote-code-execution input-validation python
1t 1c
high advisory

Thumbor Path Traversal via URL Decoding Bypass

Thumbor version 7.7.7 and earlier is vulnerable to arbitrary file read via a path traversal flaw in file_loader.py, where security checks are performed before decoding percent-encoded traversal sequences.

Thumbor web-application-vulnerability hmac-bypass image-processing cve-2026-53501 ssrf web-application input-validation
1r 2t 1c 1i
medium advisory

Auth.js getToken() Vulnerability Leads to Denial of Service

A vulnerability in the Auth.js `getToken()` helper function (next-auth and @auth/core) allows unauthenticated attackers to trigger an uncaught exception via a malformed `Authorization: Bearer` header, leading to a per-request denial of service in affected applications.

@auth/core +1 denial-of-service vulnerability web-application javascript input-validation
1t
high threat

Improper Input Validation in boazsegev facil.io WebSocket Frame Parser (CVE-2026-16632)

A high-severity improper input validation vulnerability, CVE-2026-16632, exists in the `websocket_on_protocol_error` function of the `boazsegev facil.io` WebSocket Frame Parser, allowing a remote unauthenticated attacker to manipulate the `on_message` argument with a publicly available exploit, potentially leading to denial of service or information disclosure.

exploited facil.io 0.7.4 +4 vulnerability web-application input-validation remote-code-execution
1t 1c
low threat

CVE-2026-0238: Palo Alto Networks Broker VM Improper Input Validation

CVE-2026-0238 is an improper input validation vulnerability in Palo Alto Networks Broker VM that allows an authenticated administrator to inject arbitrary content into certain fields, affecting versions 30.0 prior to 30.0.24.

exploited Broker VM vulnerability input validation
2r
medium advisory

Free5GC UDM Information Disclosure via Malformed Request

The free5GC UDM component fails to validate the `supi` path parameter in six GET handlers, allowing an unauthenticated attacker to inject control characters and trigger a `500 Internal Server Error` that exposes internal infrastructure details.

udm information-disclosure input-validation free5GC
2r 2t 1c
high advisory

OpenClaw Input Validation Vulnerability Allows Privilege Escalation

OpenClaw before version 2026.4.10 contains an input validation vulnerability (CVE-2026-43534) allowing external hook metadata to be enqueued as trusted system events, enabling attackers to escalate privileges.

OpenClaw input-validation privilege-escalation cve-2026-43534
2r 1t 1c
high advisory

Microsoft PowerShell Improper Input Validation Vulnerability (CVE-2026-26143)

An improper input validation vulnerability (CVE-2026-26143) in Microsoft PowerShell allows an unauthorized local attacker to bypass security features.

cve-2026-26143 powershell input-validation bypass-uac windows
2r 1t 1c
medium advisory

Adobe ColdFusion Improper Input Validation Vulnerability (CVE-2026-27306)

An improper input validation vulnerability in Adobe ColdFusion versions 2023.18, 2025.6, and earlier (CVE-2026-27306) could lead to arbitrary code execution if a privileged user opens a specially crafted malicious file.

cve-2026-27306 coldfusion code execution input validation
2r 1t 1c
critical advisory

Rapid7 Velociraptor Improper Input Validation Vulnerability

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability allowing authenticated remote attackers to achieve remote code execution on the server.

Velociraptor rce input-validation linux
2r 1t 1c
critical advisory

Android-ImageMagick7 Improper Input Validation Vulnerability (CVE-2026-4755)

A CWE-20 improper input validation vulnerability exists in MolotovCherry Android-ImageMagick7 before version 7.1.2-11, potentially allowing for remote code execution or denial of service.

Android-ImageMagick7 cve-2026-4755 android imagemagick input-validation remote-code-execution
2r 3t