CWE-179: Incorrect Behavior Order: Early Validation
The product validates input before applying protection mechanisms that modify the input, which could allow an attacker to bypass the validation via dangerous inputs that only arise after the modification.
5 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-4759 — Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via
- CVE-2024-41686 — Password Policy Bypass Vulnerability
- CVE-2026-3832 — Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
- CVE-2026-49414 — ASLR bypass for setuid executables via procctl(2)
Recently published
- CVE-2026-49414 — ASLR bypass for setuid executables via procctl(2)
- CVE-2026-3832 — Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
- CVE-2025-4759 — Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via
- CVE-2024-41686 — Password Policy Bypass Vulnerability