CWE-1327: Binding to an Unrestricted IP Address
The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.
24 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-61934 — AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327
- CVE-2025-3621 — Remote Code Execution in ProTNS ActADUR
- CVE-2026-82456 — argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
- CVE-2026-20212 — Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
- CVE-2026-0481 — Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per
- CVE-2026-42503 — Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/gopls
- CVE-2026-55641 — 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2025-11538 — Keycloak-server: debug default bind address
- CVE-2026-75021 — fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address
- CVE-2024-47176 — cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
- CVE-2024-36105 — dbt allows Binding to an Unrestricted IP Address via socketsocket
- CVE-2026-28395 — OpenClaw 2026.1.14-1 < 2026.2.12 - Unintended Public Binding of Chrome Extension Relay via Wildcard cdpUrl
- CVE-2026-16713 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2024-49384 — Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products
- CVE-2024-49383 — Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products a
- CVE-2024-49382 — Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-24015 — Apache IoTDB: Insecure Default Configuration Vulnerability
Recently published
- CVE-2026-75021 — fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address
- CVE-2026-20212 — Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
- CVE-2026-82456 — argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-16713 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2026-55641 — 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2026-0481 — Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per
- CVE-2026-42503 — Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/gopls
- CVE-2026-24015 — Apache IoTDB: Insecure Default Configuration Vulnerability
- CVE-2026-28395 — OpenClaw 2026.1.14-1 < 2026.2.12 - Unintended Public Binding of Chrome Extension Relay via Wildcard cdpUrl
- CVE-2025-11538 — Keycloak-server: debug default bind address
- CVE-2025-61934 — AutomationDirect Productivity Suite Binding to an Unrestricted IP Address CWE-1327
- CVE-2025-3621 — Remote Code Execution in ProTNS ActADUR
- CVE-2024-49384 — Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products
- CVE-2024-49383 — Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products a
- CVE-2024-49382 — Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products
- CVE-2024-47176 — cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
- CVE-2024-36105 — dbt allows Binding to an Unrestricted IP Address via socketsocket