VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,608)

page 103 of 131
  • CVE-2023-30954LowNov 15, 2023
    risk 0.18cvss 2.7epss 0.00

    The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized.

  • CVE-2026-7846LowMay 5, 2026
    risk 0.17cvss 2.6epss 0.00

    A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component OpenAI-Compatible File Upload API. Such manipulation of the argument…

  • CVE-2026-41913LowApr 28, 2026
    risk 0.17cvss 3.7epss 0.00

    OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exploit this by sending multiple simultaneous authentication attempts to…

  • CVE-2025-10216LowSep 10, 2025
    risk 0.17cvss 2.6epss 0.00

    A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argument giftvouchercouponcode results in race condition. The attack may be launched…

  • CVE-2024-1949LowFeb 29, 2024
    risk 0.17cvss 2.6epss 0.00

    A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to gain unauthorized access to individual posts' contents via carefully timed post creation while another user deletes posts.

  • CVE-2022-2583LowDec 27, 2022
    risk 0.17cvss 3.7epss 0.00

    A race condition can cause incorrect HTTP request routing.

  • CVE-2021-43980LowSep 28, 2022
    risk 0.17cvss 3.7epss 0.02

    The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and…

  • CVE-2018-3759LowJun 13, 2018
    risk 0.17cvss 3.7epss 0.01

    private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the…

  • CVE-2026-34849LowApr 13, 2026
    risk 0.16cvss 2.5epss 0.00

    UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-32018LowMar 19, 2026
    risk 0.16cvss 3.6epss 0.00

    OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. Attackers can exploit unsynchronized read-modify-write operations without locking to cause registry…

  • CVE-2021-43566LowJan 11, 2022
    risk 0.16cvss 2.5epss 0.00

    All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS race to allow a directory to be created in an area of the server file system not exported under the share definition. Note that SMB1 has to be enabled, or the share also available…

  • CVE-2021-29948LowJun 24, 2021
    risk 0.16cvss 2.5epss 0.00

    Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

  • CVE-2019-8757LowDec 18, 2019
    risk 0.16cvss 2.5epss 0.00

    A race condition existed when reading and writing user preferences. This was addressed with improved state handling. This issue is fixed in macOS Catalina 10.15. The "Share Mac Analytics" setting may not be disabled when a user deselects the switch to share analytics.

  • CVE-2019-11191LowApr 12, 2019
    risk 0.16cvss 2.5epss 0.01

    The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and thus the…

  • CVE-2017-1346LowSep 25, 2017
    risk 0.16cvss 2.5epss 0.00

    IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.

  • CVE-2026-35353LowApr 22, 2026
    risk 0.14cvss 3.3epss 0.00

    The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently changing them to the requested mode via a separate chmod system call. In multi-user…

  • CVE-2026-34851LowApr 13, 2026
    risk 0.14cvss 2.2epss 0.00

    Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-19975LowAug 17, 2026
    risk 0.13cvss 3.1epss 0.00

    A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-check time-of-use. The attack may be…

  • CVE-2026-10654LowJun 30, 2026
    risk 0.13cvss 3.1epss 0.00

    A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a simultaneous bidirectional session disconnect. When the local device has initiated a session teardown (state BT_RFCOMM_STATE_DISCONNECTING, DISC sent, RTX…

  • CVE-2026-10565LowJun 2, 2026
    risk 0.13cvss 3.1epss 0.00

    A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP Handover. Performing a manipulation results in race condition. The attack can be initiated remotely. The…