CWE-1389: Incorrect Parsing of Numbers with Different Radices
The product parses numeric input assuming base 10 (decimal) values, but it does not account for inputs that use a different base number (radix).
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2026-69257 — Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
- CVE-2018-25242 — One Search 1.1.0.0 Denial of Service
- CVE-2026-47160 — Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass
- CVE-2024-26015 — An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, v
Recently published
- CVE-2026-69257 — Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
- CVE-2026-47160 — Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2018-25242 — One Search 1.1.0.0 Denial of Service
- CVE-2024-26015 — An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, v