NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables de
Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing d
EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3,
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave st
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to re
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibi
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclos
Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel acces
Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost do
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fiel
Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious us
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed c
Frequently Asked Questions
What is CWE-672?
CWE-672 (CWE-672) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-672?
There are 25 CVE records associated with CWE-672 in our database. Of these, 2 are critical severity, 7 are high severity, and 10 are medium severity.
How can I protect against CWE-672 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-672 using AI-powered security agents.
Detect CWE-672 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-672 vulnerabilities across your infrastructure.
Get Started