Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-178
Weakness type CWE-178 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 56 | 55 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▃▅█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 1 · 2026-05 0 · 2026-06 13 · 2026-07 7 · 2026-08 11 · 2026-09 22 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2020-12812 | 9.8 | 98.8 | KEV | Fortinet FortiOS |
| CVE-2026-53595 | 9.4 | 79.5 | — | FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on… |
| CVE-2026-58057 | 2.3 | 74.3 | — | Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity |
| CVE-2026-49336 | 5.5 | 66.6 | — | @microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redir… |
| CVE-2026-73270 | 8.2 | 59.2 | — | httpd mod_auth directory protection bypassed by request path casing on case-insensitive… |
| CVE-2026-3833 | 7.4 | 58.1 | — | Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison |
| CVE-2026-45062 | 8.1 | 53.5 | — | FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP F… |
| CVE-2026-45135 | 8.1 | 50.5 | — | Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files |
| CVE-2026-48595 | 8.2 | 50.3 | — | Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Midd… |
| CVE-2026-73416 | 6.1 | 50.0 | — | jupyterlab: PyPI extension blocklist package-name canonicalization bypass |
| CVE-2026-54567 | 7.5 | 48.2 | — | Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override… |
| CVE-2026-77560 | 8.1 | 47.5 | — | Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insens… |
| CVE-2026-72721 | 5.3 | 46.1 | — | Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison |
| CVE-2026-90982 | 5.3 | 46.1 | — | @fastify/static vulnerable to route guard bypass via path case-folding |
| CVE-2026-86770 | 8.6 | 45.3 | — | Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation |
| CVE-2026-72836 | 9.2 | 44.0 | — | FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass |
| CVE-2026-62673 | 8.2 | 43.3 | — | Grav: .htaccess file extension rules bypass via case variation on case-insensitive file… |
| CVE-2026-59335 | 8.7 | 42.7 | — | Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads … |
| CVE-2026-83612 | 8.7 | 42.4 | — | xmldom: HTML raw-text closing-tag case mismatch causes output amplification |
| CVE-2026-84428 | 7.5 | 42.5 | — | fastify vulnerable to header validation bypass via incomplete schema case normalization |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| caddyserver | 3 |
| getgrav | 3 |
| red hat | 3 |
| authelia | 2 |
| jupyterlab | 2 |
| nuxt | 2 |
| openclaw | 2 |
| @fastify/static | 1 |
| @xmldom | 1 |
| aiven-open | 1 |
| ash-project | 1 |
| bitbonsai | 1 |
| cloud foundry | 1 |
| discourse | 1 |
| djangoproject | 1 |