CWE-573: Improper Following of Specification by Caller
The product does not follow or incorrectly follows the specifications as required by the implementation language, environment, framework, protocol, or platform.
7 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-41583 — ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling
- CVE-2026-28498 — Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
- CVE-2025-69202 — axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
- CVE-2025-69287 — BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability
- CVE-2026-59998 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th
- CVE-2025-46330 — Snowflake Connector for C/C++ retries malformed requests
Recently published
- CVE-2026-59998 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th
- CVE-2026-41583 — ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling
- CVE-2026-28498 — Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
- CVE-2025-69287 — BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability
- CVE-2025-69202 — axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
- CVE-2025-46330 — Snowflake Connector for C/C++ retries malformed requests
More specific weaknesses
- CWE-103 — Struts: Incomplete validate() Method Definition
- CWE-104 — Struts: Form Bean Does Not Extend Validation Class
- CWE-253 — Incorrect Check of Function Return Value
- CWE-358 — Improperly Implemented Security Check for Standard
- CWE-475 — Undefined Behavior for Input to API
- CWE-577 — EJB Bad Practices: Use of Sockets
- CWE-578 — EJB Bad Practices: Use of Class Loader
- CWE-579 — J2EE Bad Practices: Non-serializable Object Stored in Session
- CWE-581 — Object Model Violation: Just One of Equals and Hashcode Defined
- CWE-628 — Function Call with Incorrectly Specified Arguments
- CWE-675 — Multiple Operations on Resource in Single-Operation Context
- CWE-695 — Use of Low-Level Functionality