Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-350
Weakness type CWE-350 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 14 | 13 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▅▄▅█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 0 · 2026-06 3 · 2026-07 2 · 2026-08 3 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-57123 | 9.8 | 58.6 | — | PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validat… |
| CVE-2026-75514 | 5.9 | 46.9 | — | BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist… |
| CVE-2026-61568 | 9.6 | 43.2 | — | @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport |
| CVE-2026-56709 | 8.7 | 35.7 | — | Grav before 3.9.2 Host Header Injection via sendInvitationEmail |
| CVE-2025-8036 | 8.1 | 34.7 | — | DNS rebinding circumvents CORS |
| CVE-2026-61743 | 6.3 | 32.7 | — | Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation |
| CVE-2026-55526 | 8.5 | 27.3 | — | PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved… |
| CVE-2026-36604 | 6.5 | 27.1 | — | — |
| CVE-2026-53708 | 6.6 | 26.5 | — | ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways… |
| CVE-2026-55391 | 7.5 | 21.3 | — | datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding |
| CVE-2026-97875 | 8.1 | 16.2 | — | DNS rebinding vulnerability in rojo serve HTTP API |
| CVE-2026-63118 | 6.9 | 15.8 | — | MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection |
| CVE-2026-12635 | 3.1 | 14.8 | — | Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab |
| CVE-2026-46611 | 5.3 | 5.4 | — | Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack |