CWE · MITRE source
CWE-187Partial String Comparison
The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.
For example, an attacker might succeed in authentication by providing a small password that matches the associated portion of the larger, correct password.
Last updated: 11 August 2026 21:18 UTC
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-41110 UPD | 8.1 | 9.9 | 0.1650 | 2024-07-24 |
CVE-2022-31802 UPD | 7.5 | 9.8 | 0.0118 | 2022-06-24 |
CVE-2026-35031 UPD | 7.1 | 9.9 | 0.0075 | 2026-04-14 |
CVE-2024-39742 UPD | 6.2 | 8.1 | 0.0076 | 2024-07-08 |
CVE-2026-55602 | 6.2 | 8.6 | 0.0037 | 2026-06-22 |
CVE-2026-30874 | 5.8 | 7.8 | 0.0030 | 2026-03-19 |
CVE-2026-34785 UPD | 5.8 | 7.5 | 0.0039 | 2026-04-02 |
CVE-2026-44837 UPD | 4.7 | 5.9 | 0.0041 | 2026-05-26 |
CVE-2026-14687 | 4.4 | 5.3 | 0.0033 | 2026-07-05 |
CVE-2026-45692 | 4.2 | 5.4 | 0.0017 | 2026-06-23 |
CVE-2026-62750 | 4.2 | 6.5 | 0.0000 | 2026-08-11 |
CVE-2025-23384 UPD | 3.2 | 3.7 | 0.0027 | 2025-03-11 |