SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any
A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unha
We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable wh
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li
Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core
The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely c
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's Byt
ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m
Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementati
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a H
Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the H
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic w
An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The v
[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.
Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unau
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS c
@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when
OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A s
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing s
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst
find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS a
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-cont
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially c
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough r
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vi
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet
Frequently Asked Questions
What is CWE-248?
CWE-248 (CWE-248) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-248?
There are 110 CVE records associated with CWE-248 in our database. Of these, 1 are critical severity, 47 are high severity, and 41 are medium severity.
How can I protect against CWE-248 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-248 using AI-powered security agents.
Detect CWE-248 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-248 vulnerabilities across your infrastructure.
Get Started