CWE-681: Incorrect Conversion between Numeric Types
When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.
64 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-21693 — iccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cpp
- CVE-2026-21688 — iccDEV has Type Confusion in SIccCalcOp::ArgsPushed() at IccProfLib/IccMpeCalc.cpp
- CVE-2026-24856 — iccDEV has UB runtime error in <icTagTypeSignature>
- CVE-2026-21673 — iccDEV has Integer Overflow/Underflow in CIccXmlArrayType::ParseTextCountNum()
- CVE-2026-4602 — Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to hand
- CVE-2026-55768 — GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service
- CVE-2025-58063 — CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
- CVE-2026-82457 — su-exec through 0.3 Privilege Escalation via Numeric User ID
- CVE-2026-45258 — Multiple vulnerabilities in the sound(4) mmap path
- CVE-2026-24192 — NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between n
- CVE-2025-10543 — In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,
- CVE-2026-24174 — NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor
- CVE-2026-34550 — iccDEV: UB at IccIO.cpp
- CVE-2026-34548 — iccDEV: UB at IccUtilXml.cpp
- CVE-2026-34610 — leancrypto: Integer truncation in X.509 name parser enables certificate identity impersonation
- CVE-2026-53466 — ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
- CVE-2024-32481 — vyper's range(start, start + N) reverts for negative numbers
- CVE-2026-9143 — Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks in CodeGen
- CVE-2026-84963 — Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
- CVE-2026-84970 — Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser
Recently published
- CVE-2026-84963 — Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser
- CVE-2026-84966 — BSON element injection via NUL-embedded document keys in builder append
- CVE-2026-84970 — Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser
- CVE-2026-82522 — libjxl < 0.12.0 Container Box Parser Integer Underflow via 32-bit Size Truncation
- CVE-2026-82457 — su-exec through 0.3 Privilege Escalation via Numeric User ID
- CVE-2026-75145 — FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer
- CVE-2026-19879 — Io.undertow/undertow: undertow: http response header integrity issue due to character truncation
- CVE-2026-6426 — Qemu-kvm: vhost inflight migration vmstate integer type mismatch causes out-of-bounds access
- CVE-2026-55768 — GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service
- CVE-2026-53466 — ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
- CVE-2026-45258 — Multiple vulnerabilities in the sound(4) mmap path
- CVE-2026-53923 — vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow
- CVE-2026-9143 — Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks in CodeGen
- CVE-2026-24192 — NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between n
- CVE-2026-34945 — Wasmtime leaks host data with 64-bit tables and Winch
- CVE-2026-24174 — NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor
- CVE-2026-34610 — leancrypto: Integer truncation in X.509 name parser enables certificate identity impersonation
- CVE-2026-34550 — iccDEV: UB at IccIO.cpp
- CVE-2026-34548 — iccDEV: UB at IccUtilXml.cpp
- CVE-2026-4602 — Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to hand