CWE-610: Externally Controlled Reference to a Resource in Another Sphere
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
81 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-79256 — Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attack
- CVE-2024-32980 — Spin contains a potential network sandbox escape for specifically configured Spin applications
- CVE-2025-22144 — Account Takeover in NamelessMC
- CVE-2024-42168 — HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability
- CVE-2024-24760 — Mailcow Docker Container Exposure to Local Network
- CVE-2025-2875 — CWE-610: Externally Controlled Reference to a Resource in Another Sphere vulnerability exists that could cause a loss of
- CVE-2025-9065 — Rockwell Automation ThinManager® Server-Side Request Forgery Vulnerability
- CVE-2024-47773 — Anonymous cache poisoning via XHR requests in Discourse
- CVE-2026-47358 — Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded
- CVE-2026-47357 — Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem
- CVE-2025-7824 — Jinher OA XmlHttp.aspx xml external entity reference
- CVE-2025-7823 — Jinher OA ProjectScheduleDelete.aspx xml external entity reference
- CVE-2025-7523 — Jinher OA DelTemp.aspx xml external entity reference
- CVE-2025-11341 — Jinher OA type xml external entity reference
- CVE-2025-11140 — Bjskzy Zhiyou ERP com.artery.richclient.RichClientService openForm xml external entity reference
- CVE-2025-10816 — Jinher OA XML text xml external entity reference
- CVE-2025-10092 — Jinher OA XML Type xml external entity reference
- CVE-2025-10091 — Jinher OA XML Type xml external entity reference
- CVE-2026-0522 — Local File Inclusion in the File Upload/Download Process
- CVE-2026-28722 — Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
Recently published
- CVE-2026-19032 — jackson-databind resolves attacker-controlled URI schemes when deserializing java.nio.file.Path
- CVE-2026-21810 — HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and downloading code without integrity checking
- CVE-2026-79256 — Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attack
- CVE-2026-78966 — Externally controlled reference in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web
- CVE-2026-62960 — Git for Windows: Server-advertised bundle-uri can trigger outbound SMB callbacks via UNC and file:// paths on Windows
- CVE-2026-76572 — pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference
- CVE-2026-68562 — Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering
- CVE-2026-55389 — datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
- CVE-2026-55390 — Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
- CVE-2026-12879 — Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
- CVE-2026-12788 — zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 XML Parser import xml external entity reference
- CVE-2026-45760 — Apache Camel K: Camel K Cross-Namespace Build Deputy Attack
- CVE-2026-47358 — Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded
- CVE-2026-47357 — Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem
- CVE-2026-0522 — Local File Inclusion in the File Upload/Download Process
- CVE-2026-32008 — OpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard
- CVE-2026-28722 — Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
- CVE-2026-28721 — Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
- CVE-2026-3404 — thinkgem JeeSite Endpoint CasOutHandler.java xml external entity reference
- CVE-2026-2536 — opencc JFlow Workflow WF_Admin_AttrFlow.java Imp_Done xml external entity reference