boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-409

Weakness type CWE-409 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
98980

Monthly trend

▁▁▂▁▁▄▆▅█▂

2026-01 2 · 2026-02 0 · 2026-03 4 · 2026-04 2 · 2026-05 2 · 2026-06 13 · 2026-07 21 · 2026-08 18 · 2026-09 32 · 2026-10 4

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-499757.590.6—Apache HTTP Server: mod_http2 denial of service
CVE-2026-214418.986.6—urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects…
CVE-2026-750476.567.0——
CVE-2026-15267.565.8—undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-def…
CVE-2026-485868.762.5—Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-416087.562.5—Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
CVE-2026-491587.562.5—Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
CVE-2026-297857.560.7—NATS Server panic via malicious compression on leafnode port
CVE-2026-157097.557.8—Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded…
CVE-2026-444328.957.7—urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
CVE-2026-693045.957.6—ASP.NET Core Denial of Service Vulnerability
CVE-2026-401928.757.3—Pillow is vulnerable to a FITS GZIP decompression bomb
CVE-2026-463877.556.9—Suricata http2: decompression bomb can cause denial of service in Suricata
CVE-2026-890597.554.8—Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)
CVE-2026-400368.754.7—Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
CVE-2026-825208.754.5—parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments
CVE-2026-598038.753.1—rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
CVE-2026-835997.553.1—Netdata: WebSocket Decompression Bomb
CVE-2026-689818.853.0—Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
CVE-2026-242647.552.3——

Most-affected vendors