CWE-134: Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
141 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-23113 — A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
- CVE-2024-9129 — Format String Injection in Zend Server
- CVE-2024-42330 — JS - Internal strings in HTTP headers
- CVE-2025-48826 — A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially craf
- CVE-2024-39529 — Junos OS: SRX Series: If DNS traceoptions are configured in a DGA or tunnel detection scenario specific DNS traffic leads to a PFE crash
- CVE-2025-24359 — ASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape
- CVE-2026-17136 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-63073 — Untrusted Sender DN Used as Format String in CMP Response Validation
- CVE-2026-3509 — CODESYS Control Audit Log Format String DoS
- CVE-2025-55298 — ImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code execution
- CVE-2025-36202 — IBM webMethods Integration code execution
- CVE-2024-58366 — SurrealDB before 1.1.1 Format String via Scripting Functions
- CVE-2026-50211 — Exposed Factory Testing App Boundaries
- CVE-2026-12174 — D-Link DCS-935L HTTP rhea snprintf format string
- CVE-2026-12004 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-67244 — A format string vulnerability was found in the Notification OAuth settings of ADM
- CVE-2026-57877 — GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)
- CVE-2025-48388 — FreeScout Has Insufficient Protection Against CRLF-injection
- CVE-2026-33210 — Ruby JSON has a format string injection vulnerability
- CVE-2026-81574 — Format String Vulnerability in Logger
Recently published
- CVE-2026-16821 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-81574 — Format String Vulnerability in Logger
- CVE-2026-63073 — Untrusted Sender DN Used as Format String in CMP Response Validation
- CVE-2026-17136 — Vulnerabilities in IBM AIX and PowerVM VIOS
- CVE-2026-68553 — Coturn: Format String Injection via TURN USERNAME/REALM into hiredis Redis Command
- CVE-2026-15961 — Power System Information Disclosure
- CVE-2026-12004 — Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
- CVE-2026-67244 — A format string vulnerability was found in the Notification OAuth settings of ADM
- CVE-2026-18188 — A format string vulnerability was found in the Rsync Backup on the ADM
- CVE-2026-18187 — A format string vulnerability was found in the Internal Backup on the ADM
- CVE-2026-18186 — A stored format string vulnerability was found in the FTP Backup on the ADM
- CVE-2026-6390 — Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.
- CVE-2024-58366 — SurrealDB before 1.1.1 Format String via Scripting Functions
- CVE-2026-15809 — Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env
- CVE-2026-15680 — Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability
- CVE-2026-46465 — Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
- CVE-2026-57877 — GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)
- CVE-2026-10828 — A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPor
- CVE-2026-12174 — D-Link DCS-935L HTTP rhea snprintf format string
- CVE-2026-6250 — Authenticated Format String Injection on TP-Link Tapo C110