CWE-366: Race Condition within a Thread
If two threads of execution use a resource simultaneously, there exists the possibility that resources may be used while invalid, in turn making the state of execution undefined.
15 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-10630 — A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to
- CVE-2025-31115 — XZ has a heap-use-after-free bug in threaded .xz decoder
- CVE-2026-23684 — Race condition vulnerability in SAP Commerce Cloud
- CVE-2026-22819 — Outray has a Race Condition in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts
- CVE-2026-3904 — Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library
Recently published
- CVE-2026-3904 — Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library
- CVE-2026-23684 — Race condition vulnerability in SAP Commerce Cloud
- CVE-2026-22819 — Outray has a Race Condition in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts
- CVE-2025-31115 — XZ has a heap-use-after-free bug in threaded .xz decoder
- CVE-2024-10630 — A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to