CWE-641: Improper Restriction of Names for Files and Other Resources
The product constructs the name of a file or other resource using input from an upstream component, but it does not restrict or incorrectly restricts the resulting name.
16 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-50023 — yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
- CVE-2019-25623 — Luminance Studio 2.17 Denial of Service via Malformed Input
- CVE-2024-47260 — 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient
- CVE-2026-46581 — In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or
Recently published
- CVE-2026-46581 — In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or
- CVE-2026-50023 — yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
- CVE-2019-25623 — Luminance Studio 2.17 Denial of Service via Malformed Input
- CVE-2024-47260 — 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient