CWE-436: Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
92 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-25291 — ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
- CVE-2025-25292 — Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
- CVE-2026-57580 — authentik: Account Takeover via SAML NameID Comment Truncation
- CVE-2026-27444 — Header Email Address Parsing
- CVE-2026-85184 — @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
- CVE-2026-6270 — @fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
- CVE-2026-41248 — Official Clerk JavaScript SDKs: Middleware-based route protection bypass
- CVE-2026-33808 — @fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
- CVE-2026-33807 — @fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes
- CVE-2026-14198 — @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values
- CVE-2026-0958 — Interpretation Conflict in GitLab
- CVE-2026-49473 — @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
- CVE-2026-73615 — Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
- CVE-2026-73614 — Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
- CVE-2026-40165 — authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier Truncation
- CVE-2026-49332 — Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams
- CVE-2026-47767 — Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
- CVE-2026-48788 — Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
- CVE-2025-54368 — uv is vulnerable to ZIP payload obfuscation through parsing differentials
- CVE-2024-29034 — CarrierWave's Content-Type allowlist bypass vulnerability which possibly leads to XSS remained
Recently published
- CVE-2026-87627 — Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leve
- CVE-2026-82537 — Roo-Code 3.54.0 Auto-Approve Bypass via Shell Parser Word-Boundary Mismatch
- CVE-2026-85184 — @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request target
- CVE-2026-84394 — fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
- CVE-2026-63435 — Mail: Email address spoofing via malformed RFC 2047 encoded-words
- CVE-2026-75931 — fast-uri vulnerable to host confusion via skipped IDN canonicalization on scheme-relative references
- CVE-2026-57580 — authentik: Account Takeover via SAML NameID Comment Truncation
- CVE-2026-73846 — CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
- CVE-2026-73615 — Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch
- CVE-2026-73614 — Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation
- CVE-2026-49473 — @cedar-policy/authorization-for-expressjs has an authorization bypass via query string manipulation
- CVE-2026-18246 — IBM i is Affected By security restrictions bypass in Navigator for i
- CVE-2026-68968 — Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id
- CVE-2026-18427 — @fastify/static vulnerable to route guard bypass via non-canonical path segments
- CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks
- CVE-2026-18446 — fast-uri vulnerable to host confusion via backslash authority introducer
- CVE-2026-14643 — undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
- CVE-2026-67201 — V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
- CVE-2026-49332 — Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams
- CVE-2026-16221 — fast-uri vulnerable to host confusion via literal backslash authority delimiter