Cyber Resilience

CWE · MITRE source

CWE-183Permissive List of Allowed Inputs

Abstraction: Base · CVEs in our corpus: 45

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 4 mapping(s) from 1 framework(s): CAPEC 4 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A06:2025 Insecure Design.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.5.2
  • V4.4.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-34907.510.00.00622026-06-17
CVE-2026-543166.89.10.00402026-06-23
CVE-2026-29514 6.78.80.00782026-05-04
CVE-2025-53762 6.48.70.00742025-07-18
CVE-2020-25696 6.27.50.02702020-11-23
CVE-2026-339796.28.20.00382026-03-27
CVE-2026-673456.08.10.00312026-07-30
CVE-2025-594575.87.70.00812025-09-17
CVE-2024-1654 5.77.20.01312024-03-14
CVE-2026-413875.77.80.00242026-04-28
CVE-2026-598025.78.20.00192026-07-08
CVE-2025-24349 5.57.10.00602025-04-30
CVE-2026-21915 5.56.70.02242026-04-09
CVE-2026-42043 5.57.20.00662026-04-24
CVE-2026-501895.47.20.00332026-06-24
CVE-2026-466085.37.40.00232026-06-25
CVE-2022-34450 5.16.70.00422023-02-11
CVE-2023-4399 5.16.60.01082023-10-17
CVE-2026-356495.16.50.00282026-04-10
CVE-2026-408995.16.50.00392026-04-16
CVE-2026-43574 5.06.50.00242026-05-05
CVE-2024-38522 4.96.30.00352024-06-28
CVE-2026-2302 4.96.50.00202026-02-10
CVE-2026-2303 4.96.50.00222026-02-10
CVE-2026-4509 4.96.30.00292026-03-21