CWE-704: Incorrect Type Conversion or Cast
The product does not correctly convert an object, resource, or structure from one type to a different type.
77 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-41646 — RevPi Webstatus application is vulnerable to an authentication bypass
- CVE-2025-41648 — Pilz: Authentication Bypass in IndustrialPI Webstatus
- CVE-2026-21692 — iccDEV has Type Confusion in ToXmlCurve() at IccXML/IccLibXML/IccMpeXml.cpp
- CVE-2026-15826 — User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
- CVE-2026-10080 — Boards plugin panics on WebSocket command with non-string field types
- CVE-2026-24856 — iccDEV has UB runtime error in <icTagTypeSignature>
- CVE-2026-21673 — iccDEV has Integer Overflow/Underflow in CIccXmlArrayType::ParseTextCountNum()
- CVE-2024-43058 — Incorrect Type Conversion or Cast in Multimedia Frameworks
- CVE-2024-47181 — Unaligned memory access in RPL option processing in Contiki-NG
- CVE-2024-39590 — Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of Op
- CVE-2024-39589 — Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of Op
- CVE-2024-28130 — An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS D
- CVE-2024-5436 — Type Confusion in Snapchat Lenscore
- CVE-2026-25613 — An unsafe cast in the MongoDB query planner can result in a segmentation fault.
- CVE-2026-25503 — iccDEV Has Type Confusion in CIccTagEmbeddedHeightImage::Validate()
- CVE-2025-62494 — Type confusion in string addition in QuickJS
- CVE-2025-54429 — Polkadot Frontier's constructing smart contract can bypass precompile address bounding
- CVE-2025-21088 — WebApp crash via improper validation of proto style in attachments
- CVE-2025-20072 — Mobile crash via improper validation of proto style in attachments
- CVE-2026-45685 — OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
Recently published
- CVE-2026-87546 — Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote att
- CVE-2026-50278 — iccDEV: CIccEmbedIO::Read8() size_t underflow
- CVE-2026-10080 — Boards plugin panics on WebSocket command with non-string field types
- CVE-2026-15826 — User Profile Builder <= 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter
- CVE-2026-53798 — rsync < 3.5.0 Privilege Confusion via name-converter uid/gid mapping
- CVE-2026-73429 — Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
- CVE-2026-18675 — Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid
- CVE-2026-59871 — node-tar: Process crash via PAX numeric path type confusion
- CVE-2026-55076 — Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
- CVE-2026-48140 — Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream
- CVE-2026-46690 — unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race
- CVE-2026-45685 — OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
- CVE-2026-44324 — free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
- CVE-2023-7345 — Ledger Live hw-app-eth EIP-712 Message Parsing Integer Truncation
- CVE-2026-44223 — vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
- CVE-2026-42576 — apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
- CVE-2026-40613 — Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)
- CVE-2026-34379 — OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB decompression)
- CVE-2021-4456 — Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact
- CVE-2026-25613 — An unsafe cast in the MongoDB query planner can result in a segmentation fault.