Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-130

MITRE ↗

CWE-130

2
CRITICAL
16
HIGH
20
MEDIUM
42 CVEs
9.8
CVE-2026-43125

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The le

9.1
CVE-2026-42216

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the

8.8
CVE-2026-22046

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

8.8
CVE-2026-22047

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

8.8
CVE-2026-22255

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

8.8
CVE-2026-22861

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio

8.8
CVE-2026-58096

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by

8.6
CVE-2026-5367

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration

8.2
CVE-2026-45615

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod

8.1
CVE-2026-35547

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali

7.8
CVE-2026-58097

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the

7.5
CVE-2026-31635

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length

7.5
CVE-2026-33846

A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises

7.5
CVE-2026-54466

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions

7.5
CVE-2026-14587

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask

7.5
CVE-2026-81575

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which con

7.4
CVE-2026-4371

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside th

7.4
CVE-2026-41035

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiv

6.5
CVE-2025-48022

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ

6.5
CVE-2026-40199

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pa

6.5
CVE-2026-5265

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original

6.5
CVE-2026-48685

FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attrib

6.5
CVE-2026-67292

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor

6.3
CVE-2026-60060

Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide

5.9
CVE-2026-45681

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0

5.5
CVE-2026-62423

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

5.5
CVE-2026-62424

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

5.4
CVE-2026-71402

An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capt

5.3
CVE-2026-33936

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El

5.3
CVE-2026-41898

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo

5.3
CVE-2026-5766

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-

5.3
CVE-2026-48487

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a

5.1
CVE-2026-25571

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component doe

5.1
CVE-2026-25572

A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component doe

4.8
CVE-2026-34831

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Cont

4.8
CVE-2026-47692

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9

4.8
CVE-2026-26081

HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise

4.0
CVE-2026-33555

An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches

CVE-2026-3868

An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Be

CVE-2026-9054

An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel p

CVE-2026-6432

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

CVE-2026-5706

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to s

Frequently Asked Questions

What is CWE-130?

CWE-130 (CWE-130) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-130?

There are 44 CVE records associated with CWE-130 in our database. Of these, 2 are critical severity, 16 are high severity, and 20 are medium severity.

How can I protect against CWE-130 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-130 using AI-powered security agents.

Detect CWE-130 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-130 vulnerabilities across your infrastructure.

Get Started