Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-1289 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 10 | 10 | 0 |
▃▅█▆▁
2026-04 1 · 2026-05 2 · 2026-06 4 · 2026-07 3 · 2026-08 0
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47729 | 6.5 | 72.3 | — | Squid: Memory disclosure in FTP gateway |
| CVE-2026-39821 | 9.6 | 48.6 | — | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| CVE-2026-46644 | 6.9 | 32.8 | — | symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-o… |
| CVE-2026-60074 | 7.5 | 32.1 | — | Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal… |
| CVE-2026-33810 | 7.5 | 27.1 | — | Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509 |
| CVE-2026-49942 | 7.3 | 24.0 | — | Net::CIDR::Set versions through 0.20 for Perl did not validate network masks |
| CVE-2026-47674 | 5.3 | 15.9 | — | Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 |
| CVE-2026-50090 | 6.1 | 13.9 | — | Aqara OAuth redirect_uri validation bypass |
| CVE-2026-49940 | 6.5 | 9.7 | — | Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks |
| CVE-2026-42462 | 7.0 | 6.8 | — | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring |
| Vendor | CVEs |
|---|---|
| go standard library | 2 |
| rrwo | 2 |
| aqara | 1 |
| fedify-dev | 1 |
| golang.org/x/net | 1 |
| honojs | 1 |
| sbeck | 1 |
| squid-cache | 1 |
| symfony | 1 |