CWE-1289: Improper Validation of Unsafe Equivalence in Input
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-33496 — Ory Oathkeeper has an authentication bypass by cache key confusion
- CVE-2026-50090 — Aqara OAuth redirect_uri validation bypass
- CVE-2026-35039 — fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
- CVE-2026-33515 — Squid has issues in ICP message handling
- CVE-2026-49942 — Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
- CVE-2026-39972 — Mercure has a Topic Selector Cache Key Collision
- CVE-2026-42462 — Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
- CVE-2026-33729 — OpenFGA has an Authorization Bypass through cached keys
- CVE-2026-46644 — symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence
- CVE-2026-41239 — DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
- CVE-2026-34080 — xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
- CVE-2026-3563 — Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth
- CVE-2026-49940 — Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
- CVE-2026-47729 — Squid: Memory disclosure in FTP gateway
- CVE-2026-45191 — Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
- CVE-2026-45190 — Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass
- CVE-2026-19953 — URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
- CVE-2026-22569 — Incorrect startup configuration in ZCC
- CVE-2024-12224 — idna accepts Punycode labels that do not produce any non-ASCII when decoded
- CVE-2026-74994 — inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
Recently published
- CVE-2026-76977 — Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)
- CVE-2026-74994 — inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
- CVE-2026-19953 — URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep
- CVE-2026-60074 — Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check
- CVE-2026-47729 — Squid: Memory disclosure in FTP gateway
- CVE-2026-46644 — symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence
- CVE-2026-50090 — Aqara OAuth redirect_uri validation bypass
- CVE-2026-42462 — Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
- CVE-2026-49942 — Net::CIDR::Set versions through 0.20 for Perl did not validate network masks
- CVE-2026-49940 — Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks
- CVE-2026-47674 — Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
- CVE-2026-45191 — Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass
- CVE-2026-45190 — Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass
- CVE-2026-41213 — @node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codes
- CVE-2026-41239 — DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
- CVE-2026-39972 — Mercure has a Topic Selector Cache Key Collision
- CVE-2026-34080 — xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception
- CVE-2026-35039 — fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
- CVE-2026-22569 — Incorrect startup configuration in ZCC
- CVE-2026-33729 — OpenFGA has an Authorization Bypass through cached keys