CWE-454: External Initialization of Trusted Variables or Data Stores
The product initializes critical internal variables or data stores using inputs that can be modified by untrusted actors.
4 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-54003 — Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
- CVE-2025-36244 — IBM AIX privilege escalation
- CVE-2026-48980 — pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
Recently published
- CVE-2026-54003 — Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
- CVE-2026-48980 — pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
- CVE-2025-36244 — IBM AIX privilege escalation