Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-405
Weakness type CWE-405 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 18 | 18 | 0 |
Monthly trend
▂▅▁▆█▆
2026-05 1 · 2026-06 3 · 2026-07 0 · 2026-08 4 · 2026-09 6 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-47774 | 7.5 | 63.1 | — | Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK am… |
| CVE-2026-72914 | 7.5 | 56.0 | — | Mastodon: Exhausting data by an unauthenticated request to the admin retention API |
| CVE-2026-75029 | 5.3 | 52.1 | — | Message parser retains every identical singleton RDATA, enabling wire-to-work amplifica… |
| CVE-2026-87011 | 7.5 | 49.1 | — | Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in … |
| CVE-2026-54874 | 7.5 | 48.0 | — | Excessive Memory Use Buffering DTLS Records for a Future Epoch |
| CVE-2026-68531 | 2.1 | 38.1 | — | Concrete CMS below 9.5.3 is vulnerable to Authenticated Denial of Service via Unescaped… |
| CVE-2026-86432 | 6.9 | 33.9 | — | commonmark 2.0.0 before 2.8.4 Denial of Service via XML |
| CVE-2026-54224 | 7.1 | 31.6 | — | Denial of Service in UBB.threads |
| CVE-2025-32394 | 5.3 | 29.9 | — | AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock |
| CVE-2026-82309 | 4.3 | 28.9 | — | Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DN… |
| CVE-2026-23934 | 5.1 | 27.0 | — | Frontend DoS via the validate.api.exists action |
| CVE-2026-23930 | 5.3 | 26.9 | — | Frontend DoS via the popup.testtriggerexpr action |
| CVE-2026-104423 | 8.7 | 25.6 | — | Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification |
| CVE-2026-104431 | 8.7 | 25.6 | — | Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification |
| CVE-2026-104425 | 6.9 | 21.1 | — | Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions |
| CVE-2026-103880 | — | 8.6 | — | Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored… |
| CVE-2026-8594 | 6.2 | 7.4 | — | Text::LineFold versions through 2019.001 for Perl duplicate the output based on the num… |
| CVE-2026-84310 | 4.8 | 7.1 | — | pypdf: Possible long runtimes/large memory usage when retrieving outlines |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| zcashfoundation | 3 |
| zabbix | 2 |
| apache | 1 |
| concrete cms | 1 |
| envoyproxy | 1 |
| isc | 1 |
| mastodon | 1 |
| nezumi | 1 |
| open-webui | 1 |
| openssl | 1 |
| py-pdf | 1 |
| significant-gravitas | 1 |
| thephpleague | 1 |
| ubb systems | 1 |