CWE-420Base2 in KEV

Unprotected Alternate Channel

Draft in the CWE catalog · 37 CVEs mapped

37
CVEs mapped
2
In KEV
7.3
Median CVSS
What it is

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Recent examples
5.3cvss
CVE-2026-77639

CVE-2026-77639 - MEDIUM Severity Vulnerability

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

MEDIUMno explanation yet
0%
epss
6.9cvss
CVE-2026-40435

BIG-IP httpd access control vulnerability

When configured, IP-based access restrictions for httpd do not cover all endpoints, which may allow connections from blocked addresses.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

MEDIUMno explanation yet
0%
epss
6.5cvss
CVE-2026-43505

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relaying of unauthenticated traffic can occur.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-420
Abstraction
Base
Structure
Simple
Status
Draft