Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1286
Weakness type CWE-1286 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 30 | 30 | 0 |
Monthly trend
▂▂▃▁▃█▂▃▅▁
2026-01 1 · 2026-02 1 · 2026-03 3 · 2026-04 0 · 2026-05 3 · 2026-06 11 · 2026-07 1 · 2026-08 3 · 2026-09 7 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-13878 | 7.5 | 95.2 | — | Malformed BRID/HHIT records can cause named to terminate unexpectedly |
| CVE-2026-21527 | 6.5 | 94.7 | — | Microsoft Exchange Server Spoofing Vulnerability |
| CVE-2026-48059 | 8.7 | 57.7 | — | Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to M… |
| CVE-2026-7307 | 7.5 | 57.3 | — | Keycloak: keycloak: denial of service via specially crafted saml input |
| CVE-2026-42579 | 9.1 | 56.6 | — | Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder) |
| CVE-2026-27889 | 7.5 | 56.5 | — | NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead |
| CVE-2026-33218 | 7.5 | 56.5 | — | NATS has pre-auth server panic via leafnode handling |
| CVE-2026-25679 | 7.5 | 56.2 | — | Incorrect parsing of IPv6 host literals in net/url |
| CVE-2026-87082 | 7.5 | 50.9 | — | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label v… |
| CVE-2026-87080 | 9.1 | 48.5 | — | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a nam… |
| CVE-2026-83611 | 6.9 | 47.8 | — | xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a l… |
| CVE-2026-72916 | 6.3 | 46.1 | — | Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses |
| CVE-2026-57026 | 8.7 | 37.7 | — | Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP i… |
| CVE-2026-88009 | 8.8 | 36.3 | — | Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypass… |
| CVE-2026-50131 | 8.6 | 34.3 | — | Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl a… |
| CVE-2026-0931 | 6.9 | 32.9 | — | Denial-of-service vulnerability in M-Files Server |
| CVE-2025-8873 | 8.7 | 30.3 | — | Arista EOS Dataplane Denial of Service via Malformed IPsec Packet |
| CVE-2026-100902 | 5.7 | 24.5 | — | Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper improper validation of syntactic… |
| CVE-2026-69211 | 4.8 | 23.4 | — | Http4s: Set-Cookie rendering does not escape attribute delimiters |
| CVE-2026-88260 | 8.7 | 22.6 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| qualcomm | 5 |
| dräger | 3 |
| nats-io | 2 |
| netty | 2 |
| @xmldom | 1 |
| arista networks | 1 |
| barco | 1 |
| brainzcompany | 1 |
| fedify-dev | 1 |
| go standard library | 1 |
| guzzle | 1 |
| http4s | 1 |
| isc | 1 |
| juniper networks | 1 |
| m-files | 1 |