CWE-1023: Incomplete Comparison with Missing Factors
The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.
16 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-7473 — Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
- CVE-2026-4599 — Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Fact
- CVE-2026-4748 — pf silently ignores certain rules
- CVE-2025-62000 — BullWall Ransomware Containment incomplete file inspection
- CVE-2026-24255 — NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash
- CVE-2026-14199 — Session takeover via Auth Proxy cache key collision
- CVE-2026-53859 — OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
- CVE-2026-53839 — OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
- CVE-2026-48761 — Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content
- CVE-2025-46722 — vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
- CVE-2024-5528 — Incomplete Comparison with Missing Factors in GitLab
- CVE-2026-54713 — CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
- CVE-2026-48587 — Potential exposure of private data via whitespace padding in Vary header
Recently published
- CVE-2026-14199 — Session takeover via Auth Proxy cache key collision
- CVE-2026-54713 — CakePHP Queue: Incomplete Comparison in getUniqueId vulnerable to collisions
- CVE-2026-24255 — NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash
- CVE-2026-48761 — Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content
- CVE-2026-53859 — OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency
- CVE-2026-53839 — OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation
- CVE-2026-7473 — Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
- CVE-2026-48587 — Potential exposure of private data via whitespace padding in Vary header
- CVE-2026-4748 — pf silently ignores certain rules
- CVE-2026-4599 — Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Fact
- CVE-2025-62000 — BullWall Ransomware Containment incomplete file inspection
- CVE-2025-46722 — vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
- CVE-2024-5528 — Incomplete Comparison with Missing Factors in GitLab