CWE-1286: Improper Validation of Syntactic Correctness of Input
The product receives input that is expected to be well-formed - i.e., to comply with a certain syntax - but it does not validate or incorrectly validates that the input complies with the syntax.
80 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-55085 — Web http client: Unchecked Server-Side Malicious Packet Issue
- CVE-2025-41719 — Sauter: Improper Validation of user-controlled data
- CVE-2026-21917 — Junos OS: SRX Series: Specifically malformed SSL packet causes FPC crash
- CVE-2025-11573 — Denial of Service issue in Amazon.IonDotnet
- CVE-2026-25513 — FacturaScripts has SQL Injection vulnerability in API ORDER BY Clause
- CVE-2025-43878 — F5OS-A/C CLI vulnerability
- CVE-2024-0218 — DoS on IDS parsing of malformed Radius packets in Guardian before 23.4.1
- CVE-2024-51982 — Unauthenticated Denial of Service (DoS) via malformed PJL request affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, and Ricoh.
- CVE-2025-30415 — Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protec
- CVE-2025-24346 — A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivil
- CVE-2025-0638 — Routinator crashes when illegal characters are present in manifest file names
- CVE-2026-57026 — Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
- CVE-2026-33778 — Junos OS: SRX Series, MX Series: When a specifically malformed first ISAKMP packet is received kmd/iked crashes
- CVE-2025-8873 — Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2025-24812 — A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) (All versions < V4.7), S
- CVE-2026-6442 — Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface
- CVE-2026-0663 — Denial of Service condition in M-Files Server
- CVE-2025-10954 — Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic
- CVE-2025-54995 — Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Recently published
- CVE-2026-83611 — xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
- CVE-2026-72916 — Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
- CVE-2026-0931 — Denial-of-service vulnerability in M-Files Server
- CVE-2026-25292 — Improper Validation of Syntactic Correctness of Input in Automotive Linux OS
- CVE-2026-57026 — Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
- CVE-2026-55767 — Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2025-8873 — Arista EOS Dataplane Denial of Service via Malformed IPsec Packet
- CVE-2019-25720 — Dräger SC Monitoring Devices DoS via Malformed Network Packet
- CVE-2021-4479 — Dräger Atlan A350 1.00 <= 1.01 DoS via Medibus Interface
- CVE-2019-25723 — Dräger Perseus A500 2.00-2.02 DoS via Medibus Interface
- CVE-2026-24092 — Improper Validation of Syntactic Correctness of Input in Display
- CVE-2026-24091 — Improper Validation of Syntactic Correctness of Input in Display
- CVE-2026-24089 — Improper Validation of Syntactic Correctness of Input in Kernel
- CVE-2026-24087 — Improper Validation of Syntactic Correctness of Input in Kernel
- CVE-2026-10099 — XX-Net V5.16.6 WebSocket Frame Parsing Data Corruption via simple_http_server.py
- CVE-2026-7307 — Keycloak: keycloak: denial of service via specially crafted saml input
- CVE-2026-0983 — Denial of service vulnerability in M-Files Server
- CVE-2026-6442 — Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface
- CVE-2026-40198 — Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass
More specific weaknesses
- CWE-112 — Missing XML Validation