Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-176
Weakness type CWE-176 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 13 | 12 | 1 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁█▂▂▇▁
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 5 · 2026-07 1 · 2026-08 1 · 2026-09 4 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-43093 | 7.3 | 51.9 | KEV | Android Framework |
| CVE-2026-48618 | 6.5 | 87.8 | — | — |
| CVE-2026-45062 | 8.1 | 53.5 | — | FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP F… |
| CVE-2026-45135 | 8.1 | 50.5 | — | Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files |
| CVE-2026-59890 | 6.1 | 32.5 | — | setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (… |
| CVE-2026-93990 | 8.7 | 32.3 | — | Expat before 2.8.5 Malformed UTF-16 Acceptance via Unchecked Surrogate |
| CVE-2026-93751 | 6.9 | 31.9 | — | uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars |
| CVE-2025-71316 | 9.2 | 30.1 | — | SQLite sqldiff remote code execution via argument injection |
| CVE-2026-86105 | 6.0 | 27.2 | — | Fireware OS Improper Authorization in Access Portal Reverse Proxy |
| CVE-2026-23950 | 5.9 | 15.8 | — | node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on mac… |
| CVE-2026-49401 | 8.4 | 8.5 | — | Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS) |
| CVE-2026-81869 | 5.1 | 6.9 | — | OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation |
| CVE-2026-14978 | 5.5 | 2.9 | — | Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended f… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| caddyserver | 1 |
| denoland | 1 |
| garycourt | 1 |
| 1 | |
| hashicorp | 1 |
| isaacs | 1 |
| libexpat | 1 |
| nodejs | 1 |
| open-telemetry | 1 |
| php | 1 |
| pypa | 1 |
| sqlite | 1 |
| watchguard | 1 |