$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-407 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-407

전체 목록

49건

CVE-2026-82760Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated a…0.5%높음8.2
CVE-2026-92091A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate val…0.5%보통5.9
CVE-2026-82729Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CP…0.5%보통6.3
CVE-2026-90776Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparse…0.5%높음8.7
CVE-2026-44639NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqt…0.4%낮음3.7
CVE-2026-94658Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thri…0.4%높음8.7
CVE-2026-85494Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, M…0.4%높음8.7
CVE-2026-96287Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thr…0.4%높음8.2
CVE-2026-94653Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thri…0.4%높음8.2
CVE-2026-94655Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apac…0.4%높음8.2
CVE-2026-96292Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift L…0.4%높음8.2
CVE-2026-19668A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a pa…0.4%보통5.3
CVE-2026-65634Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenti…0.4%높음8.2
CVE-2026-92365A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functional…0.4%보통5.3
CVE-2026-104844PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior t…0.4%보통5.9
CVE-2026-87822t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.from…0.4%높음8.7
CVE-2026-92987roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without…0.4%높음8.7
CVE-2026-85446MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new …0.4%높음8.7
CVE-2023-54395PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket proc…0.3%보통5.3
CVE-2026-42772Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arri…0.3%보통5.3
CVE-2026-67419RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a …0.3%높음7.1
CVE-2026-87721Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.…0.3%높음8.7
CVE-2026-49250Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.prope…0.3%높음8.7
CVE-2026-86434league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability i…0.3%높음8.7
CVE-2026-86433commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extens…0.3%높음8.7
CVE-2026-86429The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic pa…0.3%높음8.7
CVE-2026-104426Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value…0.3%높음8.2
CVE-2026-86430league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code bloc…0.3%높음8.7
CVE-2026-102277The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21…0.3%보통5.3
CVE-2026-102997pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially…0.3%높음8.7
CVE-2026-102994pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-ob…0.3%높음8.7
CVE-2026-102999pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedd…0.3%높음8.7
CVE-2024-58382league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing…0.3%높음8.7
CVE-2026-86428commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtens…0.3%높음8.7
CVE-2026-86435commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extensio…0.3%높음8.7
CVE-2026-100700nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback re…0.3%높음8.7
CVE-2026-103604Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUt…0.3%높음8.7
CVE-2026-86349Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit th…0.2%보통4.3
CVE-2026-12882Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Ma…0.2%보통4.3
CVE-2026-104182stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footpr…0.1%보통6.2
CVE-2026-71429stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footpr…0.1%보통6.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.