CWE-1288: Improper Validation of Consistency within Input
The product receives a complex input with multiple elements or fields that must be consistent with each other, but it does not validate or incorrectly validates that the input is actually consistent.
27 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-39515 — Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash
- CVE-2025-9999 — Improper validation of payload elements
- CVE-2026-18794 — OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite
- CVE-2024-12093 — Improper Validation of Consistency within Input in GitLab
- CVE-2025-2885 — Root metadata version not validated in tough
- CVE-2024-5953 — 389-ds-base: malformed userpassword hash may cause denial of service
- CVE-2026-15943 — Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change
- CVE-2026-73219 — CVAT: Denial of service with regards to automatic annotation
- CVE-2025-46722 — vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
- CVE-2026-18238 — OOBR in rpcap client in libpcap before 1.10.7
- CVE-2026-14781 — Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to userinfo email
- CVE-2026-9689 — Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri allows response parameter duplication - #ghi-604
- CVE-2026-18209 — Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check
- CVE-2025-10929 — Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111
Recently published
- CVE-2026-18238 — OOBR in rpcap client in libpcap before 1.10.7
- CVE-2026-18794 — OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite
- CVE-2026-73219 — CVAT: Denial of service with regards to automatic annotation
- CVE-2026-18209 — Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check
- CVE-2026-15943 — Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change
- CVE-2026-14781 — Keycloak-services: keycloak-services: oidc email_verified claim incorrectly applied to userinfo email
- CVE-2026-9689 — Keycloak: org.keycloak.protocol.oidc: http parameter pollution in oidc redirect uri allows response parameter duplication - #ghi-604
- CVE-2025-10929 — Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111
- CVE-2025-9999 — Improper validation of payload elements
- CVE-2025-46722 — vLLM has a Weakness in MultiModalHasher Image Hashing Implementation
- CVE-2024-12093 — Improper Validation of Consistency within Input in GitLab
- CVE-2025-2885 — Root metadata version not validated in tough
- CVE-2024-39515 — Junos OS and Junos OS Evolved: With BGP traceoptions enabled, receipt of specifically malformed BGP update causes RPD crash
- CVE-2024-5953 — 389-ds-base: malformed userpassword hash may cause denial of service