Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For e
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due
fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuil
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to w
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypasse
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran
Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior t
Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out
Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allo
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values,
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not valida
Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Ar
Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in t
@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7
Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassin
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amoun
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an
Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 unti
Frequently Asked Questions
What is CWE-1289?
CWE-1289 (CWE-1289) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1289?
There are 28 CVE records associated with CWE-1289 in our database. Of these, 5 are critical severity, 6 are high severity, and 14 are medium severity.
How can I protect against CWE-1289 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1289 using AI-powered security agents.
Detect CWE-1289 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1289 vulnerabilities across your infrastructure.
Get Started