Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-173
Weakness type CWE-173 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 4 | 4 | 0 |
Monthly trend
█▅▅
2026-08 2 · 2026-09 1 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-10050 | 8.7 | 48.5 | — | Digest authentication lossy encoding |
| CVE-2026-19611 | 7.4 | 44.4 | — | Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: p… |
| CVE-2026-103276 | 6.9 | 12.1 | — | Ghost before 6.20.0 File Read via URL Encoding Bypass |
| CVE-2026-81638 | 2.1 | 7.7 | — | Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ash-project | 1 |
| eclipse foundation | 1 |
| red hat | 1 |
| tryghost | 1 |