Cyber Resilience

CWE · MITRE source

CWE-1289Improper Validation of Unsafe Equivalence in Input

Abstraction: Base · CVEs in our corpus: 34

The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.

Attackers can sometimes bypass input validation schemes by finding inputs that appear to be safe, but will be dangerous when processed at a lower layer or by a downstream component. For example, a simple XSS protection mechanism might try to validate that an input has no "<script>" tags using case-sensitive matching, but since HTML is case-insensitive when processed by web browsers, an attacker could inject "<ScrIpT>" and trigger XSS.

Last updated: 21 August 2026 20:21 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V5.2.2
  • V9.1.3
  • V10.4.6
  • V2.2.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-62718 7.39.90.01192026-04-09
CVE-2026-33729 7.19.80.00242026-03-27
CVE-2026-39821 6.99.60.00662026-05-22
CVE-2026-35039 6.79.10.00212026-04-06
CVE-2024-12224 6.48.80.00212025-05-30
CVE-2026-50090 6.49.30.00232026-06-12
CVE-2026-33810 6.28.20.00342026-04-08
CVE-2026-33496 6.18.10.00382026-03-26
CVE-2024-45179 5.97.20.02602024-10-09
CVE-2024-422195.87.80.00292024-08-06
CVE-2026-33806 5.87.50.00412026-04-15
CVE-2026-60074 5.87.50.00392026-07-30
CVE-2026-49942 5.67.30.00312026-06-04
CVE-2026-48710 5.56.50.01842026-05-26
CVE-2026-335155.46.50.01042026-03-26
CVE-2026-477295.46.50.01502026-07-16
CVE-2026-424625.27.00.00172026-06-10
CVE-2024-45308 5.16.50.00552024-09-02
CVE-2026-412395.16.80.00252026-04-23
CVE-2026-45190 5.16.50.00312026-05-10
CVE-2026-45191 5.16.50.00302026-05-10
CVE-2026-49940 5.06.50.00202026-06-04
CVE-2022-0675 4.75.60.00922022-03-02
CVE-2026-41213 4.65.90.00262026-04-23
CVE-2026-35634.35.50.00342026-03-17