Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-185
Weakness type CWE-185 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 9 | 9 | 0 |
Monthly trend
▅▁▁█▅▅██▁
2026-02 1 · 2026-03 0 · 2026-04 0 · 2026-05 2 · 2026-06 1 · 2026-07 1 · 2026-08 2 · 2026-09 2 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-25896 | 9.3 | 40.5 | — | fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names |
| CVE-2026-56021 | 6.9 | 39.0 | — | Webmin information disclosure via regex pattern |
| CVE-2026-45065 | 2.3 | 26.1 | — | Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-S… |
| CVE-2026-64655 | 2.1 | 25.6 | — | GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN M… |
| CVE-2026-88021 | 7.1 | 24.7 | — | Consul vulnerable to an authorization bypass in the Connect service mesh |
| CVE-2026-54506 | 7.6 | 22.0 | — | Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field |
| CVE-2026-47674 | 5.3 | 21.7 | — | Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 |
| CVE-2026-73425 | 3.7 | 17.3 | — | @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePa… |
| CVE-2026-48147 | 6.5 | 5.4 | — | Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injecti… |