Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-407 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 64 | 61 | 0 |
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▇█▆
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 6 · 2026-06 19 · 2026-07 21 · 2026-08 15
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-43485 | 7.5 | 86.5 | — | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43484 | 7.5 | 86.0 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2024-43483 | 7.5 | 85.7 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2026-55968 | 8.7 | 63.0 | — | Apache Thrift: Node.js quadratic-time DoS in server receive transports |
| CVE-2026-54892 | 8.7 | 50.6 | — | Plug: quadratic-time decoding of nested query/body parameters enables denial of service |
| CVE-2026-55685 | 8.7 | 50.3 | — | React Router: Unauthenticated Denial of Service via Inefficient Route Matching |
| CVE-2026-66046 | 8.7 | 49.5 | — | Expat Denial of Service via storeAtts() Quadratic Complexity |
| CVE-2026-64644 | 6.3 | 49.4 | — | Next.js: Denial of Service in the Image Optimization API using SVGs |
| CVE-2026-44390 | 6.9 | 47.3 | — | Unbounded name compression in certain cases causes degradation of service |
| CVE-2026-41292 | 6.6 | 47.3 | — | Long list of incoming EDNS options degrades performance |
| CVE-2026-42504 | 7.5 | 44.2 | — | Quadratic complexity in WordDecoder.DecodeHeader in mime |
| CVE-2026-70453 | 8.7 | 42.3 | — | rsync < 3.5.0 Algorithmic Complexity DoS via hash_search() |
| CVE-2026-3276 | 6.3 | 39.9 | — | Potential DoS via quadratic complexity in unicodedata.normalize() |
| CVE-2026-59094 | 8.7 | 38.9 | — | Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Do… |
| CVE-2026-68750 | 8.2 | 36.9 | — | Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exh… |
| CVE-2026-56860 | 5.9 | 36.9 | — | Avoid quadratic complexity in resolvePath in net/url |
| CVE-2026-45664 | 5.3 | 36.8 | — | ImageMagick: Policy Bypass in MNG coder could |
| CVE-2026-58226 | 8.7 | 36.6 | — | Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax |
| CVE-2026-59880 | 8.7 | 36.2 | — | Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set |
| CVE-2026-59869 | 7.5 | 35.5 | — | js-yaml: YAML merge-key chains can force quadratic CPU consumption |
| Vendor | CVEs |
|---|---|
| nodeca | 5 |
| lepture | 4 |
| messagepack-csharp | 3 |
| microsoft | 3 |
| nlnet labs | 3 |
| andialbrecht | 2 |
| elastic | 2 |
| go standard library | 2 |
| python software foundation | 2 |
| apache | 1 |
| bytedance | 1 |
| davegamble | 1 |
| elixir-mint | 1 |
| elixir-plug | 1 |
| elysiajs | 1 |