Cyber Resilience

CWE · MITRE source

CWE-187Partial String Comparison

Abstraction: Variant · CVEs in our corpus: 12

The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.

For example, an attacker might succeed in authentication by providing a small password that matches the associated portion of the larger, correct password.

Last updated: 11 August 2026 21:18 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • ID.RA-01
  • AC-3 Access Enforcement
  • SA-11 Developer Testing and Evaluation
  • PR.PS-06
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V10.4.1

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-41110 8.19.90.16502024-07-24
CVE-2022-31802 7.59.80.01182022-06-24
CVE-2026-35031 7.19.90.00752026-04-14
CVE-2024-39742 6.28.10.00762024-07-08
CVE-2026-556026.28.60.00372026-06-22
CVE-2026-308745.87.80.00302026-03-19
CVE-2026-34785 5.87.50.00392026-04-02
CVE-2026-44837 4.75.90.00412026-05-26
CVE-2026-146874.45.30.00332026-07-05
CVE-2026-456924.25.40.00172026-06-23
CVE-2026-627504.26.50.00002026-08-11
CVE-2025-23384 3.23.70.00272025-03-11