A08:2025 Software or Data Integrity Failures
Code or data is trusted without integrity verification — insecure deserialization, unsigned updates, CI/CD compromise paths.
Related on the LLM side: OWASP Top 10 for LLMs LLM04:2025.
Member CWEs (14)
- CWE-345 Insufficient Verification of Data Authenticity
- CWE-353 Missing Support for Integrity Check
- CWE-426 Untrusted Search Path
- CWE-427 Uncontrolled Search Path Element
- CWE-494 Download of Code Without Integrity Check
- CWE-502 Deserialization of Untrusted Data
- CWE-506 Embedded Malicious Code
- CWE-509 Replicating Malicious Code (Virus or Worm)
- CWE-565 Reliance on Cookies without Validation and Integrity Checking
- CWE-784 Reliance on Cookies without Validation and Integrity Checking in a Security Decision
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere
- CWE-830 Inclusion of Web Functionality from an Untrusted Source
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes
- CWE-926 Improper Export of Android Application Components
Mapped NIST 800-53 r5 controls (5)
Our two-way, human-QA’d reading of how this category and each NIST 800-53 control relate. No external body publishes an OWASP→800-53 mapping, so these are our assessment.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Tagged CVEs (showing 50 most recent of 6,608)
- CVE-2026-77651
- CVE-2026-77650
- CVE-2026-77649
- CVE-2026-77646
- CVE-2026-77645
- CVE-2026-76850
- CVE-2026-76404
- CVE-2026-76395
- CVE-2026-76245
- CVE-2026-76241
- CVE-2026-76139
- CVE-2026-75987
- CVE-2026-75569
- CVE-2026-74890
- CVE-2026-74882
- CVE-2026-74875
- CVE-2026-74872
- CVE-2026-74012
- CVE-2026-73993
- CVE-2026-73851
- CVE-2026-73846
- CVE-2026-73840
- CVE-2026-73657
- CVE-2026-73533
- CVE-2026-73532
- CVE-2026-73419
- CVE-2026-73397
- CVE-2026-73389
- CVE-2026-73380
- CVE-2026-73376
- CVE-2026-73367
- CVE-2026-73366
- CVE-2026-73364
- CVE-2026-73341
- CVE-2026-73325
- CVE-2026-73076
- CVE-2026-73073
- CVE-2026-72817
- CVE-2026-72778
- CVE-2026-72719
- CVE-2026-72655
- CVE-2026-72544
- CVE-2026-71965
- CVE-2026-71858
- CVE-2026-71576
- CVE-2026-71560
- CVE-2026-71559
- CVE-2026-71558
- CVE-2026-71513
- CVE-2026-71473
Data: OWASP Top 10:2025 (CC BY-SA 4.0) · CWE memberships from cwe-api.mitre.org (meta-category CWE-1443).