CWE-480: Use of Incorrect Operator
The product accidentally uses the wrong operator, which changes the logic in security-relevant ways.
9 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-15043 — DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
- CVE-2026-4748 — pf silently ignores certain rules
- CVE-2025-52985 — Junos OS Evolved: When a control-plane firewall filter refers to a prefix-list with more than 10 entries it's not matching
- CVE-2026-63421 — Keystone: `graphql.maxTake` bypass with negative `take`
- CVE-2026-79643 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-44722 — pyzipper: Encryption bypass for small files encrypted with pyzipper
- CVE-2026-48497 — Envoy: Abnormal process termination in DNS UDP filter
Recently published
- CVE-2026-79643 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-63421 — Keystone: `graphql.maxTake` bypass with negative `take`
- CVE-2026-44722 — pyzipper: Encryption bypass for small files encrypted with pyzipper
- CVE-2026-15043 — DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
- CVE-2026-48497 — Envoy: Abnormal process termination in DNS UDP filter
- CVE-2026-4748 — pf silently ignores certain rules
- CVE-2025-52985 — Junos OS Evolved: When a control-plane firewall filter refers to a prefix-list with more than 10 entries it's not matching