CWE-475Base

Undefined Behavior for Input to API

Incomplete in the CWE catalog · 13 CVEs mapped

13
CVEs mapped
6.5
Median CVSS
What it is

The behavior of this function is undefined unless its control parameter is set to a specific value.

Recent examples
8.1cvss
CVE-2026-19311

CVE-2026-19311 - HIGH Severity Vulnerability

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2026-42009

CVE-2026-42009 - HIGH Severity Vulnerability

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.

HIGHno explanation yet
1%
epss
6.3cvss
CVE-2026-21690

iccDEV has Type Confusion in CIccTagXmlTagData::ToXml()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccTagXmlTagData::ToXml()`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-475
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)