Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1289
Weakness type CWE-1289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 23 | 23 | 1 |
Monthly trend
▃▃▄▃▂█▂
2026-04 2 · 2026-05 3 · 2026-06 4 · 2026-07 3 · 2026-08 1 · 2026-09 9 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48710 | 6.5 | 94.0 | KEV | Starlette has missing Host header validation that poisons request.url.path, bypassing p… |
| CVE-2026-47729 | 6.5 | 83.7 | — | Squid: Memory disclosure in FTP gateway |
| CVE-2025-62718 | 6.3 | 66.8 | — | Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF |
| CVE-2026-39821 | 9.6 | 51.2 | — | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| CVE-2026-89049 | 8.5 | 49.9 | — | Server-side request forgery in the Session Manager port forwarding functionality in AWS… |
| CVE-2026-86831 | 8.7 | 49.0 | — | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS |
| CVE-2026-74994 | 6.0 | 48.5 | — | inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth |
| CVE-2026-60074 | 7.5 | 48.4 | — | Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal… |
| CVE-2026-46644 | 6.9 | 43.3 | — | symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-o… |
| CVE-2026-88255 | 6.3 | 42.4 | — | mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encod… |
| CVE-2026-49942 | 7.3 | 39.9 | — | Net::CIDR::Set versions through 0.20 for Perl did not validate network masks |
| CVE-2026-76977 | 4.3 | 28.8 | — | Clickjacking vulnerability in SAPUI5(Frame Options Allowlist) |
| CVE-2026-50090 | 6.1 | 28.3 | — | Aqara OAuth redirect_uri validation bypass |
| CVE-2026-100255 | 9.8 | 26.3 | — | — |
| CVE-2026-33810 | 8.2 | 25.2 | — | Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 |
| CVE-2026-47674 | 5.3 | 21.7 | — | Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 |
| CVE-2026-97196 | 9.1 | 20.3 | — | WordPress GiveWP plugin <= 4.16.9 - Broken Authentication vulnerability |
| CVE-2026-49940 | 6.5 | 20.2 | — | Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks |
| CVE-2026-101015 | 5.5 | 19.9 | — | Trusted Domain Project OpenDMARC policy.c improper validation of unsafe equivalence in … |
| CVE-2026-42462 | 7.0 | 14.7 | — | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| aws | 2 |
| go standard library | 2 |
| rrwo | 2 |
| aqara | 1 |
| axios | 1 |
| edgelesssys | 1 |
| erlang | 1 |
| fedify-dev | 1 |
| golang.org/x/net | 1 |
| honojs | 1 |
| jetbrains | 1 |
| kludex | 1 |
| liquid web / stellarwp | 1 |
| sap_se | 1 |
| squid-cache | 1 |