CWE-1025: Comparison Using Wrong Factors
The code performs a comparison between two entities, but the comparison examines the wrong factors or characteristics of the entities, which can lead to incorrect results and resultant weaknesses.
15 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-25306 — Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2025-71377 — stoatchat before 20250210-1 Unrestricted Message History Fetch
- CVE-2026-75840 — ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
- CVE-2023-54390 — PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
- CVE-2025-32464 — HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow becau
- CVE-2026-9800 — Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
- CVE-2026-48860 — Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
- CVE-2026-40880 — Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
- CVE-2025-2888 — Improper timestamp caching during snapshot rollback in tough
- CVE-2025-2887 — Failure to detect delegated target rollback in tough
- CVE-2026-21691 — iccDEV has Type Confusion in CIccTag:IsTypeCompressed()
- CVE-2026-40227 — In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that
- CVE-2025-27839 — operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet
Recently published
- CVE-2023-54390 — PocketMine-MP before 5.3.1 Denial of Service via LoginPacket
- CVE-2026-78619 — Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically
- CVE-2026-75840 — ArcadeDB before 26.8.1 Arbitrary File Read via Unescaped Regex
- CVE-2025-71377 — stoatchat before 20250210-1 Unrestricted Message History Fetch
- CVE-2026-9800 — Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison
- CVE-2026-48860 — Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist
- CVE-2026-40880 — Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
- CVE-2026-40227 — In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that
- CVE-2026-21691 — iccDEV has Type Confusion in CIccTag:IsTypeCompressed()
- CVE-2025-32464 — HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow becau
- CVE-2025-2888 — Improper timestamp caching during snapshot rollback in tough
- CVE-2025-2887 — Failure to detect delegated target rollback in tough
- CVE-2025-25306 — Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
- CVE-2025-27839 — operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet