CWE-148Variant

Improper Neutralization of Input Leaders

Draft in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
7.5
Median CVSS
What it is

The product does not properly handle when a leading character or sequence ("leader") is missing or malformed, or if multiple leaders are used when only one should be allowed.

Recent examples
5.1cvss
CVE-2026-12862

XLSX formula injection in exports

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

MEDIUMno explanation yet
0%
epss
7.5cvss
CVE-2024-53856

rPGP Panics on Malformed Untrusted Input

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.

HIGHno explanation yet
0%
epss
8.1cvss
CVE-2023-4853

CVE-2023-4853 - HIGH Severity Vulnerability

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-148
Abstraction
Variant
Structure
Simple
Status
Draft