CWE-794Variant

Incomplete Filtering of Multiple Instances of Special Elements

Incomplete in the CWE catalog · 5 CVEs mapped

5
CVEs mapped
7.5
Median CVSS
What it is

The product receives data from an upstream component, but does not filter all instances of a special element before sending it to a downstream component.

Recent examples
9.3cvss
CVE-2026-21876

OWASP CRS has multipart bypass using multiple content-type parts

🔥 A simple multipart request can slip malicious content past your defenses! A bug in OWASP's core rule set allows a crafty attacker to bypass detection due to variable overwriting. ⚡ Think of this as a restaurant kitchen where a chef keeps replacing the previous order with the latest one on the list—if the last dish looks perfect, they might not notice the sneaky ingredient snuck in earlier! This oversight means an attacker could successfully deliver harmful payloads that could exploit your application without triggering any alarms. Imagine the chaos if your web application doesn't catch malicious charsets hidden within legitimate multipart requests!

CRITICAL
14%
epss
7.5cvss
CVE-2021-0233

Junos OS: ACX500 Series, ACX4000 Series: Denial of Service due to FFEB crash while processing high rate of specific packets.

A vulnerability in Juniper Networks Junos OS ACX500 Series, ACX4000 Series, may allow an attacker to cause a Denial of Service (DoS) by sending a high rate of specific packets to the device, resulting in a Forwarding Engine Board (FFEB) crash. Continued receipt of these packets will sustain the Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS on ACX500 Series, ACX4000 Series: 17.4 versions prior to 17.4R3-S2.

HIGHno explanation yet
1%
epss
8.6cvss
CVE-2021-0203

Junos OS: EX and QFX5K Series: Storm Control does not work as expected when Redundant Trunk Group is configured

On Juniper Networks EX and QFX5K Series platforms configured with Redundant Trunk Group (RTG), Storm Control profile applied on the RTG interface might not take affect when it reaches the threshold condition. Storm Control enables the device to monitor traffic levels and to drop broadcast, multicast, and unknown unicast packets when a specified traffic level is exceeded, thus preventing packets from proliferating and degrading the LAN. Note: this issue does not affect EX2200, EX3300, EX4200, and EX9200 Series. This issue affects Juniper Networks Junos OS on EX Series and QFX5K Series: 15.1 versions prior to 15.1R7-S7; 16.1 versions prior to 16.1R7-S8; 17.2 versions prior to 17.2R3-S4; 17.3 versions prior to 17.3R3-S8; 17.4 versions prior to 17.4R2-S11, 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R3-S5; 18.3 versions prior to 18.3R2-S4, 18.3R3-S2; 18.4 versions prior to 18.4R2-S5, 18.4R3-S3; 19.1 versions prior to 19.1R2-S2, 19.1R3-S2; 19.2 versions prior to 19.2R1-S5, 19.2R2-S1, 19.2R3; 19.3 versions prior to 19.3R2-S4, 19.3R3; 19.4 versions prior to 19.4R1-S3, 19.4R2-S1, 19.4R3; 20.1 versions prior to 20.1R1-S2, 20.1R2.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-794
Abstraction
Variant
Structure
Simple
Status
Incomplete