CWE-794: Incomplete Filtering of Multiple Instances of Special Elements
The product receives data from an upstream component, but does not filter all instances of a special element before sending it to a downstream component.
5 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-21876 — OWASP CRS has multipart bypass using multiple content-type parts
Recently published
- CVE-2026-21876 — OWASP CRS has multipart bypass using multiple content-type parts