CWE-670: Always-Incorrect Control Flow Implementation
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
89 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-55276 — Apache Tomcat: Logged effective web.xml is incomplete
- CVE-2025-24800 — Critical vulnerability in `ismp-grandpa` <v15.0.1
- CVE-2024-32971 — Defect in query plan cache may cause incorrect operations to be executed in Apollo Router
- CVE-2026-33011 — Nest Fastify HEAD Request Middleware Bypass
- CVE-2026-53404 — Apache Tomcat: Bad ornext processing in RewriteValve
- CVE-2024-5659 — Rockwell Automation Multicast Request Causes major nonrecoverable fault on Select Controllers
- CVE-2025-49091 — KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme
- CVE-2024-52811 — Acks not validated before logged to qlog leads to buffer overflow in ngtcp2
- CVE-2026-26267 — rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collide
- CVE-2025-58136 — Apache Traffic Server: A simple legitimate POST request causes a crash
- CVE-2024-37153 — Evmos's contract balance not updating correctly after interchain transaction
- CVE-2024-38365 — btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality
- CVE-2026-1874 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module and Ethernet module
- CVE-2025-32942 — SSH Tectia Server before 6.6.6 sometimes allows attackers to read and alter a user's session traffic.
- CVE-2026-7656 — Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
- CVE-2026-40960 — Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as s
- CVE-2026-40200 — An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very
- CVE-2026-48844 — Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o
- CVE-2026-40719 — Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr
- CVE-2024-53270 — HTTP/1: sending overload crashes when the request is reset beforehand in envoy
Recently published
- CVE-2026-55624 — MintyItanium Lost-Auction takes items like barrier blocks out from search GUI
- CVE-2026-72705 — Rocq Prover before 9.2.0 Guard Checker Accepts Fixpoint Passed as a Higher-Order Argument
- CVE-2026-72704 — Rocq Prover through 9.2.0 Guard Checker Trusts Corrupted Recursive Tree After Transport
- CVE-2026-72703 — Rocq Prover 8.20 before 9.2.0 Guard Checker Accepts Non-Terminating Fixpoint via Unchecked Cross-Calls
- CVE-2026-19487 — Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass
- CVE-2026-73283 — In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar
- CVE-2026-20713 — Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalati
- CVE-2026-14935 — Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check
- CVE-2026-56328 — Capgo - Integrity Issue in Release Routing via Multiple Public Channels
- CVE-2026-7656 — Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack
- CVE-2026-55276 — Apache Tomcat: Logged effective web.xml is incomplete
- CVE-2026-53404 — Apache Tomcat: Bad ornext processing in RewriteValve
- CVE-2026-56307 — Cap-go - Broken Cursor Pagination in /private/devices Endpoint
- CVE-2026-48844 — Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o
- CVE-2026-20171 — Cisco Nexus 3000 and 9000 Series Border Gateway Protocol Denial of Service Vulnerability
- CVE-2026-44928 — In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
- CVE-2026-41988 — uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6.
- CVE-2026-35343 — uutils coreutils cut Inconsistent Output Suppression with Newline Delimiters
- CVE-2026-40942 — DSF: Inverted Time Comparison in OIDC JWKS and Token Cache
- CVE-2026-41527 — KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i