Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-348
Weakness type CWE-348 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 37 | 37 | 0 |
Monthly trend
▃▆▁█▁
2026-06 6 · 2026-07 12 · 2026-08 1 · 2026-09 17 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-44046 | 2.3 | 38.9 | — | Apache APISIX: wolf-rbac plugin Identity Spoofing |
| CVE-2026-61682 | 9.9 | 30.1 | — | kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authen… |
| CVE-2026-58122 | 9.3 | 28.9 | — | Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing |
| CVE-2026-90711 | 9.1 | 24.1 | — | proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
| CVE-2026-92395 | 9.1 | 24.1 | — | @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet |
| CVE-2026-55641 | 8.2 | 23.1 | — | 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay … |
| CVE-2026-64619 | 8.7 | 20.1 | — | FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers |
| CVE-2026-63770 | 8.2 | 20.1 | — | Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass |
| CVE-2026-100653 | 8.3 | 19.0 | — | vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation |
| CVE-2026-57942 | 6.9 | 18.5 | — | LibreTranslate - IP Spoofing via X-Forwarded-For Header |
| CVE-2026-9561 | 8.8 | 18.5 | — | — |
| CVE-2026-97404 | 9.2 | 16.8 | — | — |
| CVE-2026-46415 | 8.2 | 13.0 | — | Caddy Defender trusted proxy client IP bypass |
| CVE-2026-48772 | 10.0 | 12.4 | — | ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rul… |
| CVE-2026-25552 | 6.3 | 12.0 | — | Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header |
| CVE-2026-62987 | 5.8 | 9.1 | — | Fabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/… |
| CVE-2026-101277 | 5.5 | 7.9 | — | Trusted Domain Project OpenDKIM Tag Tokenizer dkim.c dkim_process_set less trusted source |
| CVE-2020-37248 | 6.5 | 7.4 | — | — |
| CVE-2026-103592 | 6.9 | 7.0 | — | simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers |
| CVE-2026-59897 | 5.3 | 6.8 | — | Hono: API Gateway v1 adapter can drop a distinct repeated request header value during d… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| honojs | 2 |
| @fastify/proxy-addr | 1 |
| apache | 1 |
| canonical | 1 |
| codeigniter4 | 1 |
| decolua | 1 |
| dell | 1 |
| djust-org | 1 |
| eclipse foundation | 1 |
| fabiolb | 1 |
| fastify | 1 |
| forgejo | 1 |
| gitlab | 1 |
| glanceapp | 1 |
| irdeto | 1 |