Cyber Resilience

CWE · MITRE source

CWE-187Partial String Comparison

Abstraction: Variant · CVEs in our corpus: 15

The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.

For example, an attacker might succeed in authentication by providing a small password that matches the associated portion of the larger, correct password.

Last updated: 25 September 2026 21:25 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • ID.RA-01
  • AC-3 Access Enforcement
  • SA-11 Developer Testing and Evaluation
  • PR.PS-06
Detect
Catch it (CSF Detect / Respond)

—

Harden
Shrink the surface (DISA STIG)

—

Validate
Prove the fix (OWASP ASVS)
  • V10.4.1

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-41110 8.19.90.16502024-07-24
CVE-2022-31802 7.69.80.01302022-06-24
CVE-2026-35031 7.19.90.00922026-04-14
CVE-2024-39742 6.28.10.00762024-07-08
CVE-2026-556026.28.60.00382026-06-22
CVE-2026-34785 5.97.50.00522026-04-02
CVE-2026-308745.87.80.00342026-03-19
CVE-2026-878535.77.50.00482026-09-09
CVE-2026-627505.26.50.00682026-08-11
CVE-2026-44837 4.65.90.00372026-05-26
CVE-2026-146874.55.30.00532026-07-05
CVE-2026-814794.45.80.00232026-09-17
CVE-2026-456924.35.40.00242026-06-23
CVE-2025-23384 3.23.70.00272025-03-11