Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-172
Weakness type CWE-172 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 5 | 4 | 0 |
Monthly trend
▅▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▁█▅
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 0 · 2026-07 1 · 2026-08 0 · 2026-09 2 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2019-10160 | 9.8 | 92.3 | — | — |
| CVE-2026-106122 | 6.0 | 33.0 | — | RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC consumers |
| CVE-2026-48784 | 5.1 | 26.3 | — | Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Ge… |
| CVE-2026-100891 | 5.5 | 20.1 | — | Trusted Domain Project OpenDMARC Internationalized Domain Name opendmarc_policy.c opend… |
| CVE-2026-86818 | 4.8 | 15.4 | — | fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchro… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| com.rabbitmq | 1 |
| fast-uri | 1 |
| python | 1 |
| rabbitmq | 1 |
| symfony | 1 |
| trusted domain project | 1 |