Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-158 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 2 | 2 | 0 |
█▁█
2026-06 1 · 2026-07 0 · 2026-08 1
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47778 | 4.4 | 7.5 | — | Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator.… |
| CVE-2026-70603 | 6.0 | 1.0 | — | Electron: shell.openPath path validation bypass via embedded null byte |
| Vendor | CVEs |
|---|---|
| electron | 1 |
| envoyproxy | 1 |