VYPR

CWE-1327

Binding to an Unrestricted IP Address

BaseIncomplete

Description

The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1

CVEs mapped to this weakness (22)

page 2 of 2
  • CVE-2026-47873HigJul 30, 2026
    risk 0.00cvss 8.0epss 0.00

    The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

  • CVE-2026-55641HigJul 10, 2026
    risk 0.00cvss 8.2epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass API-key authentication. In the default…