Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-407
Weakness type CWE-407 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 131 | 128 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▄▅█▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 1 · 2026-03 0 · 2026-04 2 · 2026-05 7 · 2026-06 19 · 2026-07 21 · 2026-08 23 · 2026-09 45 · 2026-10 10
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-43485 | 7.5 | 87.2 | — | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43484 | 7.5 | 86.7 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43483 | 7.5 | 86.5 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2026-55968 | 8.7 | 62.5 | — | Apache Thrift: Node.js quadratic-time DoS in server receive transports |
| CVE-2026-54892 | 8.7 | 59.9 | — | Plug: quadratic-time decoding of nested query/body parameters enables denial of service |
| CVE-2026-41292 | 6.6 | 56.0 | — | Long list of incoming EDNS options degrades performance |
| CVE-2026-68750 | 8.2 | 55.1 | — | Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exh… |
| CVE-2026-59094 | 8.7 | 54.8 | — | Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Do… |
| CVE-2026-66046 | 8.7 | 53.1 | — | Expat Denial of Service via storeAtts() Quadratic Complexity |
| CVE-2026-71321 | 7.5 | 53.1 | — | Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body … |
| CVE-2026-75005 | 8.7 | 53.0 | — | Apache APISIX: Unauthenticated CPU-exhaustion DoS |
| CVE-2026-82760 | 8.2 | 52.9 | — | Superlinear base62 decoding exhausts CPU and memory in AshAuthentication API key sign-in |
| CVE-2026-40476 | 6.9 | 52.7 | — | graphql-php: Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged… |
| CVE-2026-44390 | 6.9 | 52.1 | — | Unbounded name compression in certain cases causes degradation of service |
| CVE-2026-3276 | 6.3 | 52.1 | — | Potential DoS via quadratic complexity in unicodedata.normalize() |
| CVE-2026-55685 | 8.7 | 51.8 | — | React Router: Unauthenticated Denial of Service via Inefficient Route Matching |
| CVE-2026-90776 | 8.7 | 50.9 | — | Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing |
| CVE-2026-63446 | 7.5 | 50.9 | — | Suricata app-layer: passed flows can retain transactions, causing resource exhaustion |
| CVE-2026-69184 | 7.5 | 50.9 | — | c-ares: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains |
| CVE-2026-87822 | 8.7 | 50.2 | — | t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.from… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 8 |
| thephpleague | 8 |
| nodeca | 6 |
| py-pdf | 5 |
| lepture | 4 |
| oisf | 4 |
| red hat | 4 |
| andialbrecht | 3 |
| messagepack-csharp | 3 |
| microsoft | 3 |
| nlnet labs | 3 |
| @xmldom | 2 |
| elastic | 2 |
| elixir-mint | 2 |
| go standard library | 2 |