CWE-1102: Reliance on Machine-Dependent Data Representation
The code uses a data representation that relies on low-level data representation or constructs that may vary across different processors, physical machines, OSes, or other physical components.
Last updated
Overview
CWE-1102 (Reliance on Machine-Dependent Data Representation) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
1 recorded CVEs are caused by CWE-1102 (Reliance on Machine-Dependent Data Representation). The highest-severity and most recent are shown first. 0 new CWE-1102 CVEs have been recorded so far in 2026 (1 in 2025).
Common consequences
What can happen when CWE-1102 is exploited.
Reduce Maintainability
Affects: Other
This issue makes it more difficult to maintain and/or port the product, which indirectly affects security by making it more difficult or time-consuming to find and/or fix vulnerabilities. It also might make it easier to introduce vulnerabilities.
How it happens
When it is introduced
Typically introduced during these phases of the software lifecycle.
Illustrative examples
Real CVEs that MITRE cites as examples of this weakness.
- CVE-2025-47153 — Chain: build process for JavaScript runtime environment can have inconsistent sizes for off_t (CWE-1102), allowing out-of-bounds access / segmentation fault (CWE-119)
Frequently asked questions
Common questions about CWE-1102.
- What is CWE-1102?
- The code uses a data representation that relies on low-level data representation or constructs that may vary across different processors, physical machines, OSes, or other physical components.
- What CVEs are caused by CWE-1102?
- 1 recorded CVEs are attributed to CWE-1102, including CVE-2025-47153.
- What are the consequences of CWE-1102?
- Exploiting CWE-1102 can lead to: Reduce Maintainability.
- Is CWE-1102 actively exploited?
- 1 recorded CVEs are caused by CWE-1102; none are currently in CISA's KEV catalog of actively exploited flaws.
References
- MITRE CWE definition (CWE-1102) (opens in a new tab)
- CWE-1102 vulnerabilities on NVD (opens in a new tab)
- Learn: What is a CWE?
Weakness data is sourced from the MITRE CWE catalog (v4.20). CVE associations are aggregated and kept current by RadicalNotion.AI.
Stay ahead of CWE-1102
Get alerted the moment a new CWE-1102 vulnerability affects your stack, with AI-written analysis, severity context, and remediation guidance.