Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-1333
Weakness type CWE-1333 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 122 | 116 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▄▆▆█▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 3 · 2026-04 0 · 2026-05 3 · 2026-06 17 · 2026-07 25 · 2026-08 25 · 2026-09 37 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-10270 | 6.5 | 68.2 | — | Org.keycloak:keycloak-services: keycloak denial of service |
| CVE-2026-28356 | 7.5 | 62.4 | — | ReDoS in multipart 1.3.0 - `parse_options_header()` |
| CVE-2023-6159 | 6.5 | 61.1 | — | Inefficient Regular Expression Complexity in GitLab |
| CVE-2026-44496 | 7.5 | 60.4 | — | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| CVE-2026-52778 | 9.8 | 59.6 | — | YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial … |
| CVE-2026-47138 | 8.7 | 58.5 | — | Parse Server: Pre-authentication denial of service via client version header regex back… |
| CVE-2026-4926 | 7.5 | 58.0 | — | path-to-regexp vulnerable to Denial of Service via sequential optional groups |
| CVE-2024-21538 | 7.7 | 57.3 | — | — |
| CVE-2026-71190 | 8.7 | 56.3 | — | — |
| CVE-2026-68749 | 8.2 | 55.1 | — | Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion… |
| CVE-2026-82617 | 10.0 | 54.0 | — | Apache OpenNLP, Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory buil… |
| CVE-2026-72818 | 8.7 | 53.1 | — | NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input |
| CVE-2026-62317 | 7.5 | 53.1 | — | Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing) |
| CVE-2026-92114 | 6.9 | 52.4 | — | a2ui-project a2ui Basic Catalog safe_regex.ts redos |
| CVE-2026-33079 | 8.7 | 51.5 | — | Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles |
| CVE-2026-52746 | 7.5 | 51.1 | — | JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion |
| CVE-2026-45305 | 8.7 | 50.9 | — | Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex |
| CVE-2026-45367 | 7.5 | 50.9 | — | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint |
| CVE-2026-49485 | 7.5 | 50.9 | — | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint |
| CVE-2026-55470 | 7.5 | 50.7 | — | HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| lepture | 5 |
| apache | 4 |
| facelessuser | 4 |
| jline | 4 |
| rabbitmq | 4 |
| red hat | 4 |
| axios | 3 |
| hapifhir | 3 |
| nltk | 3 |
| open-webui | 3 |
| symfony | 3 |
| @xmldom | 2 |
| andialbrecht | 2 |
| fasterxml | 2 |
| getgrav | 2 |