CWE-129: Improper Validation of Array Index
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
247 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-87500 — Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potenti
- CVE-2025-27034 — Improper Validation of Array Index in Multi-Mode Call Processor
- CVE-2024-24563 — Vyper array negative index vulnerability
- CVE-2026-31963 — HTSlib CRAM reader has heap buffer overflow due to improper validation of input
- CVE-2026-31962 — HTSlib CRAM reader has heap buffer overflow due to improper validation of input
- CVE-2025-15271 — FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability
- CVE-2025-15270 — FontForge SFD File Parsing Improper Validation of Array Index Remote Code Execution Vulnerability
- CVE-2025-0657 — ALC WebCTRL Carrier i-Vu and Gen5 Controllers Array Index out-of-range
- CVE-2025-5868 — RT-Thread lwp_syscall.c sys_thread_sigprocmask array index
- CVE-2025-5866 — RT-Thread lwp_syscall.c sys_sigprocmask array index
- CVE-2024-33044 — Improper Validation of Array Index in Hypervisor
- CVE-2025-62372 — vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
- CVE-2026-21413 — A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 a
- CVE-2025-66559 — Taiko Alethia Pacaya inbox verification pointer corruption
- CVE-2026-25585 — iccDEV vulnerable to OOB in CIccXform3DLut::Apply()
- CVE-2025-47393 — Improper Validation of Array Index in Automotive Linux OS
- CVE-2025-47361 — Improper Validation of Array Index in Automotive Software platform based on QNX
- CVE-2025-47352 — Improper Validation of Array Index in Audio
- CVE-2025-27075 — Improper Validation of Array Index in Bluetooth HOST
- CVE-2025-27067 — Improper Validation of Array Index in DSP Service
Recently published
- CVE-2026-88052 — Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynchronization
- CVE-2023-54396 — PocketMine-MP before 4.8.1 Server Crash via Banner NBT
- CVE-2026-87500 — Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potenti
- CVE-2026-0799 — OOBR and OOBW in libpcap before 1.10.7
- CVE-2026-57159 — PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance
- CVE-2026-85084 — Out-of-bounds write in TizenFX MediaBufferBase indexer setter due to missing bounds check
- CVE-2023-31308 — A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-
- CVE-2026-82327 — Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data
- CVE-2026-19318 — Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution
- CVE-2026-79775 — rclone Archive Backend SquashFS Parser Denial of Service
- CVE-2026-13212 — Zephyr virtio driver calls an arbitrary function pointer from an out-of-range used-ring descriptor id
- CVE-2026-17097 — Power System Improper Validation
- CVE-2026-16849 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-65832 — Deskflow - Unauthenticated server-controlled out-of-bounds read in ServerProxy::setOptions / translateKey modifier-table indexing
- CVE-2026-49282 — Capstone M68K and RISCV `cs_insn_name()` invalid IDs can trigger out-of-bounds reads and process crashes
- CVE-2026-73489 — Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
- CVE-2026-73564 — frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
- CVE-2026-53792 — rsync < 3.5.0 Out-of-Bounds Read via Zero-Length Checksum Block
- CVE-2026-70635 — TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index
- CVE-2026-70634 — TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator