CWE · MITRE source
CWE-187Partial String Comparison
The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.
For example, an attacker might succeed in authentication by providing a small password that matches the associated portion of the larger, correct password.
Last updated: 25 September 2026 21:25 UTC
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-41110 UPD | 8.1 | 9.9 | 0.1650 | 2024-07-24 |
CVE-2022-31802 UPD | 7.6 | 9.8 | 0.0130 | 2022-06-24 |
CVE-2026-35031 UPD | 7.1 | 9.9 | 0.0092 | 2026-04-14 |
CVE-2024-39742 UPD | 6.2 | 8.1 | 0.0076 | 2024-07-08 |
CVE-2026-55602 | 6.2 | 8.6 | 0.0038 | 2026-06-22 |
CVE-2026-34785 UPD | 5.9 | 7.5 | 0.0052 | 2026-04-02 |
CVE-2026-30874 | 5.8 | 7.8 | 0.0034 | 2026-03-19 |
CVE-2026-87853 | 5.7 | 7.5 | 0.0048 | 2026-09-09 |
CVE-2026-62750 | 5.2 | 6.5 | 0.0068 | 2026-08-11 |
CVE-2026-44837 UPD | 4.6 | 5.9 | 0.0037 | 2026-05-26 |
CVE-2026-14687 | 4.5 | 5.3 | 0.0053 | 2026-07-05 |
CVE-2026-81479 | 4.4 | 5.8 | 0.0023 | 2026-09-17 |
CVE-2026-45692 | 4.3 | 5.4 | 0.0024 | 2026-06-23 |
CVE-2025-23384 UPD | 3.2 | 3.7 | 0.0027 | 2025-03-11 |