CWE-424Class1 in KEV

Improper Protection of Alternate Path

Draft in the CWE catalog · 36 CVEs mapped

36
CVEs mapped
1
In KEV
6.8
Median CVSS
What it is

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Recent examples
8.2cvss
CVE-2026-86145

CVE-2026-86145 - HIGH Severity Vulnerability

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).

HIGHno explanation yet
0%
epss
6.5cvss
CVE-2026-58428

CVE-2026-58428 - MEDIUM Severity Vulnerability

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

MEDIUMno explanation yet
0%
epss
9.8cvss
CVE-2026-66756

CVE-2026-66756 - CRITICAL Severity Vulnerability

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-424
Abstraction
Class
Structure
Simple
Status
Draft