Common Weakness Enumeration

    CWE Definition / CWE-1289

    CWE-1289: Improper Validation of Unsafe Equivalence in Input

    The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.

    Published:24 Jun 2020
    Organization:MITRE
    Modified:11 Dec 2025

    Related Weakness

    CWE-20: Improper Input Validation

    CWE-41: Improper Resolution of Path Equivalence

    CWE-178: Improper Handling of Case Sensitivity