CWE-130: Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
95 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-14847 — Zlib compressed protocol header length confusion may allow memory read
- CVE-2026-22861 — iccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22255 — iccDEV has heap-buffer-overflow in CIccCLUT::Init() at IccProfLib/IccTagLut.cpp
- CVE-2026-22047 — iccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-22046 — iccDEV has heap-buffer-overflow in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2025-30659 — Junos OS: SRX Series: A device configured for vector routing crashes when receiving malformed traffic
- CVE-2024-37305 — Buffer overflow in deserialization in oqs-provider
- CVE-2026-67292 — FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
- CVE-2026-54466 — websocket-driver: Message corruption via abuse of protocol length headers
- CVE-2025-10458 — Bluetooth: le_conn_rsp does not sanitize CID, MTU, MPS values
- CVE-2025-29784 — NamelessMC Has Lack of Length Validation for s Parameter in GET Requests
- CVE-2024-53856 — rPGP Panics on Malformed Untrusted Input
- CVE-2026-5706 — Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements
- CVE-2026-58096 — ppp(8): missing length validation in LcpDecodeConfig()
- CVE-2026-3868 — An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Be
- CVE-2026-5367 — Ovn: ovn: information disclosure via crafted dhcpv6 packets
- CVE-2025-52949 — Junos OS and Junos OS Evolved: In an EVPN environment, receipt of specifically malformed BGP update causes RPD crash
- CVE-2026-41898 — rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer
- CVE-2026-45615 — mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OER Payload
- CVE-2025-8531 — Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03
Recently published
- CVE-2026-5706 — Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements
- CVE-2026-71402 — wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length
- CVE-2026-81575 — Missing Sanity Checks for Buffer Lengths
- CVE-2026-58097 — ppp(8): missing length validation in mp_SetEnddisc()
- CVE-2026-58096 — ppp(8): missing length validation in LcpDecodeConfig()
- CVE-2026-14587 — Unathenticated connection can hold Bolt channel open
- CVE-2026-67292 — FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
- CVE-2026-26081 — HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise
- CVE-2026-54466 — websocket-driver: Message corruption via abuse of protocol length headers
- CVE-2026-48487 — Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet
- CVE-2026-60060 — Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide
- CVE-2026-47692 — Envoy: PROXY Protocol v2 header generator emits "skipped" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream
- CVE-2026-6432 — Improper bounds validation in EmberZNet SDK
- CVE-2026-45681 — OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size
- CVE-2026-45615 — mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OER Payload
- CVE-2026-5766 — Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass
- CVE-2026-33846 — Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
- CVE-2026-35547 — Heap overflow in libnv
- CVE-2026-3868 — An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Be
- CVE-2026-41898 — rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjacent memory to the network peer