Falhas do tipo CWE-436

115 resultados

Conflito de Interpretação

Ocorre quando diferentes componentes de um sistema interpretam a mesma entrada, comando ou formato de dados de formas distintas, criando uma desconexão entre a intenção e o resultado. Um atacante explora essa divergência para contornar validações, executar ações não autorizadas ou injetar código malicioso.

Exemplo

Um firewall bloqueia requisições HTTP com 'union select' na query, mas o servidor backend interpreta sequências de espaços e comentários SQL de forma diferente do WAF. O atacante envia 'uni/**/on sel/**/ ect' que passa pelo filtro, mas o banco de dados executa como SQL injection completo.

Como mitigar

Normalize todas as entradas em um único ponto, antes de qualquer processamento, garantindo que validadores (WAF, parsers, bancos de dados) usem as mesmas regras. Implemente testes de integração que verifiquem se diferentes camadas interpretam dados idênticos da mesma maneira.

CVE-2023-45715LOWHCL BigFix Platform is susceptible to a Denial of Service attackEPSS 0.4%CVE-2026-42272HIGHHeimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretationEPSS 0.4%CVE-2024-20293MEDIUMA vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower ThEPSS 0.4%CVE-2026-67201HIGHV 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.httpEPSS 0.4%CVE-2023-52892HIGHIn phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificatesEPSS 0.4%CVE-2026-42274HIGHHeimdall: Authorization bypass via path normalization mismatchEPSS 0.4%CVE-2025-66490MEDIUMTraefik doesn't Prevent Path Normalization Bypass in Router + Middleware RulesEPSS 0.4%CVE-2026-93750HIGHhttp-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary WildcardEPSS 0.4%CVE-2026-45066LOWSymfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> MisclassificationEPSS 0.3%CVE-2026-63435MEDIUMMail: Email address spoofing via malformed RFC 2047 encoded-wordsEPSS 0.3%CVE-2026-56329MEDIUMCapgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore DecodingEPSS 0.3%CVE-2026-41248CRITICALOfficial Clerk JavaScript SDKs: Middleware-based route protection bypassEPSS 0.3%CVE-2026-81378HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-59882MEDIUMguzzlehttp/psr7: Host Confusion via Weak URI Host ValidationEPSS 0.3%CVE-2026-85184CRITICAL@fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request targetEPSS 0.3%CVE-2026-42551HIGHFlight: HTTP method override enabled by default enables CSRF escalation and middleware bypass in flightphp/coreEPSS 0.3%CVE-2026-14643MEDIUMundici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directivesEPSS 0.3%CVE-2023-22998MEDIUMIn the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table return value (expectsEPSS 0.3%CVE-2026-42273HIGHHeimdall: Case-sensitive host matching may lead to policy bypassEPSS 0.3%CVE-2026-49332HIGHOpenshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreamsEPSS 0.3%