Security Risk Category

Input Validation Security Risks — Page 7

Published vulnerability pages connected to Input Validation. Each page keeps one canonical URL and focused remediation guidance.

243 published Input Validation risks

Input Validation risks

Showing 217–243 of 243 published risks.

mediumEPSS 0.002

CVE-2026-53878 Django vulnerability

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.

CVE-2026-53878pythonweb-applicationinput-validation

Updated Jul 12, 2026

mediumEPSS 0.004

CVE-2026-56812 Phoenix Framework vulnerability

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic. This vulnerability is associated with program files assets/js/phoenix/presence.js and program routines Presence.syncState and Presence.syncDiff. The Phoenix JavaScript presence client checks whether a presence already exists with a bare truthiness test (state[key]) instead of an own-property check. Presence keys can be attacker-controlled, because applications track presences under a username or id supplied by the client. A user who joins a channel choosing a key that is an Object.prototype member name (__proto__, constructor, toString, hasOwnProperty, and similar) makes that lookup return JavaScript's built-in Object.prototype instead of undefined. Because the prototype is truthy, the code treats it as an existing presence and reads .metas.map(...) off it, which throws an uncaught TypeError. The exception propagates out of the presence message handler, so the local state is never updated and onSync() never fires. Because the malicious key is tracked on the server, it is re-pushed on every presence update and keeps re-throwing, so presence sync stays broken for every viewer of that channel topic until the attacker leaves. Both syncState and syncDiff use the same unsafe existence-check pattern. The impact is limited to the affected topic and is a read-time confusion of the prototype object, not a mutation of Object.prototype (it is not prototype pollution). This issue affects phoenix: from 1.2.0-rc.0 before 1.5.15, from 1.6.0-rc.0 before 1.6.17, from 1.7.0-rc.0 before 1.7.24, and from 1.8.0-rc.0 before 1.8.9.

CVE-2026-56812web-applicationinput-validationdenial-of-service

Updated Jul 12, 2026

highEPSS 0.026

CVE-2026-44454 Coder vulnerability

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted `dotfiles_uri` value (for example, one containing shell command substitution such as `$(...)`) could achieve command execution in their own workspace. The Create Workspace page's `mode=auto` deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled `param.dotfiles_uri` and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation. In versions 2.29.7 and 2.30.2, input validation was added to the dotfiles module to reject URIs and usernames containing special characters, and the unsafe `eval`/`sh -c` usage was removed. This eliminated the command injection at its source.

CVE-2026-44454devopsremote-code-executioninput-validation

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-58470 GNU Wget vulnerability

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

CVE-2026-58470linuxnetwork-securityinput-validation

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-58472 GNU Wget vulnerability

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

CVE-2026-58472linuxnetwork-securityinput-validationmemory-corruption

Updated Jul 12, 2026

highEPSS 0.005

CVE-2026-55076 Coder vulnerability

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined with an unconditional email-based account fallback, this enabled account takeover. The fix in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 coerces `email_verified` across bool, string and numeric types (fail-closed) and blocks the email fallback when the matched user already has a different linked IdP subject. As a workaround, ensure the IdP returns `email_verified` as a native JSON boolean. The email-fallback linking issue has no configuration workaround; upgrading is required.

CVE-2026-55076devopsinput-validationauthentication-bypass

Updated Jul 12, 2026

mediumEPSS 0.001

CVE-2026-59999 openssh vulnerability

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

CVE-2026-59999network-securityinput-validation

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-57259 pdf editor vulnerability

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.

CVE-2026-57259pdf-editorinput-validation

Updated Jul 11, 2026

highEPSS 0.003

CVE-2026-53482 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.

CVE-2026-53482network-securityinput-validationdenial-of-service

Updated Jul 11, 2026

lowEPSS 0.003

Snap7 ReadVar Request Handler Stack Buffer Overflow Vulnerability

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes deserialization. The attack requires access to the local network. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-15105industrial-controlinput-validationdenial-of-servicememory-corruption

Updated Jul 10, 2026

mediumEPSS 0.001

Google Chrome Extensions API Integer Overflow Out-of-Bounds Read Vulnerability

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2026-15108browserapi-securityinput-validationinformation-disclosure

Updated Jul 10, 2026

lowEPSS 0.001

Google Chrome Android WebAppInstalls Same-Origin Policy Bypass Vulnerability

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15115browserweb-applicationinput-validation

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Windows Codecs Sandbox Escape Vulnerability

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15122browserwindowsinput-validation

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome Passwords Same-Origin Policy Bypass Vulnerability

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15124browserinput-validation

Updated Jul 10, 2026

mediumEPSS 0.002

Google Chrome Navigation Site Isolation Bypass Vulnerability

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-15131browserinput-validation

Updated Jul 10, 2026

mediumEPSS 0.001

Nozomi Guardian and CMC Diagram and Graph Stored HTML Injection Vulnerability

A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a victim views the affected data in the Diagram tab and Graph view, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

CVE-2026-31981browserindustrial-controlinput-validationxss

Updated Jul 10, 2026

medium

Google Cloud Apigee BigQuery DAO Cross-Tenant Data Exposure Vulnerability

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.

CVE-2026-12879cloud-securityinput-validation

Updated Jul 10, 2026

critical

XAPI Database Input Validation Denial of Service Vulnerability

There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised input. This causes the database's event thread to terminate and cease further processing. 2. XAPI's UTF-8 encoder implements v3.0 of the Unicode spec, but XAPI uses libraries which conform to the stricter v3.1 of the Unicode spec. This causes some strings to be accepted as valid UTF-8 by XAPI, but rejected by other libraries in use. Notably, such strings can be entered into the database, after which the database can no longer be loaded. 3. There is no input sanitisation for Map/Set updates on objects in the XAPI database.

CVE-2025-58146virtualizationinput-validationdenial-of-service

Updated Jul 9, 2026

low

enquirer Public Package API Prototype Pollution Vulnerability

A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report.

CVE-2026-15187npmapi-securityremote-code-executioninput-validation

Updated Jul 9, 2026

high

n8n Workflow API Prototype Pollution Privilege Bypass Vulnerability

n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via the workflow API, allowing unauthenticated requests to be treated as a privileged user and exposing user and project listing endpoints. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.

CVE-2026-59206npmapi-securityinput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.012

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

CVE-2026-12569remote-code-executioninput-validationunsafe-deserialization

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.786

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

CVE-2026-34910network-securityremote-code-executioninput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.017

Android Framework Integer Overflow Vulnerability

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation.

CVE-2025-48595input-validationprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.242

Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-32201microsoftinput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.345

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

CVE-2026-6973remote-code-executioninput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.967

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

CVE-2026-34197remote-code-executioninput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.071

Adobe Acrobat and Reader Prototype Pollution Vulnerability

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution.

CVE-2026-34621remote-code-executioninput-validation

Updated Jul 9, 2026