CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data
The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.
38 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-5994 — Cache poisoning via the ECS-enabled Rebirthday Attack
- CVE-2025-40778 — Cache poisoning attacks with unsolicited RRs
- CVE-2025-40776 — Birthday Attack against Resolvers supporting ECS
- CVE-2026-1642 — NGINX vulnerability
- CVE-2026-41120 — Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust
- CVE-2025-27415 — Nuxt allows DOS via cache poisoning with payload rendering response
- CVE-2024-53848 — check-jsonschema default caching for remote schemas allows for cache confusion
- CVE-2026-35641 — OpenClaw < 2026.3.24 - Arbitrary Code Execution via .npmrc in Local Plugin/Hook Installation
- CVE-2024-42483 — ESP-NOW Replay Attacks Vulnerability
- CVE-2024-52555 — In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer
- CVE-2025-11411 — Possible domain hijacking via promiscuous records in the authority section
- CVE-2025-68269 — In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
- CVE-2024-34083 — STARTTLS unencrypted commands injection
- CVE-2026-50252 — Possible cache poisoning attack by mapping source port population per thread
- CVE-2026-42960 — Possible cache poisoning via promiscuous records for the authority section
- CVE-2025-46339 — FreshRSS vulnerable to favicon cache poisoning via proxy
- CVE-2025-20255 — A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manip
- CVE-2026-54625 — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
- CVE-2026-15387 — Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
- CVE-2026-44572 — Next.js: Middleware / Proxy redirects can be cache-poisoned
Recently published
- CVE-2026-15387 — Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
- CVE-2026-54625 — django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
- CVE-2026-50252 — Possible cache poisoning attack by mapping source port population per thread
- CVE-2026-41120 — Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust
- CVE-2026-46342 — Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
- CVE-2026-42960 — Possible cache poisoning via promiscuous records for the authority section
- CVE-2026-44572 — Next.js: Middleware / Proxy redirects can be cache-poisoned
- CVE-2026-35641 — OpenClaw < 2026.3.24 - Arbitrary Code Execution via .npmrc in Local Plugin/Hook Installation
- CVE-2026-1642 — NGINX vulnerability
- CVE-2025-68269 — In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
- CVE-2025-1680 — An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switch
- CVE-2025-40778 — Cache poisoning attacks with unsolicited RRs
- CVE-2025-11411 — Possible domain hijacking via promiscuous records in the authority section
- CVE-2025-5994 — Cache poisoning via the ECS-enabled Rebirthday Attack
- CVE-2025-40776 — Birthday Attack against Resolvers supporting ECS
- CVE-2025-46339 — FreshRSS vulnerable to favicon cache poisoning via proxy
- CVE-2025-20255 — A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manip
- CVE-2025-27415 — Nuxt allows DOS via cache poisoning with payload rendering response
- CVE-2024-53848 — check-jsonschema default caching for remote schemas allows for cache confusion
- CVE-2024-52555 — In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer