Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-436
Weakness type CWE-436 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 52 | 51 | 2 |
Monthly trend
▂▁▁▁▁▁▁▂▁▁▃▅█▇█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 8 · 2026-07 13 · 2026-08 11 · 2026-09 14 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-63030 | 9.8 | 95.5 | KEV | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to R… |
| CVE-2025-48384 | 8.0 | 90.7 | KEV | Git allows arbitrary code execution through broken config quoting |
| CVE-2026-25223 | 7.5 | 57.6 | — | Fastify's Content-Type header tab character allows body validation bypass |
| CVE-2026-68968 | 7.5 | 53.3 | — | Apache Airflow: Authorization bypass in the Backfill API through conflicting interpreta… |
| CVE-2026-47767 | 8.3 | 52.3 | — | Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV… |
| CVE-2026-17084 | 6.0 | 52.3 | — | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 |
| CVE-2026-40165 | 8.7 | 50.7 | — | authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifi… |
| CVE-2026-73614 | 8.7 | 50.7 | — | Network-AI ClaudeHookBridge Deny Pattern Bypass via Truncation |
| CVE-2026-6322 | 7.5 | 50.5 | — | fast-uri vulnerable to host confusion via percent-encoded authority delimiters |
| CVE-2026-18427 | 7.5 | 49.8 | — | @fastify/static vulnerable to route guard bypass via non-canonical path segments |
| CVE-2026-73615 | 8.7 | 49.6 | — | Network-AI SandboxPolicy before 5.15.1 Blocklist Bypass via Quote Mismatch |
| CVE-2026-56669 | 7.5 | 48.3 | — | Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict |
| CVE-2026-57580 | 9.4 | 46.3 | — | authentik: Account Takeover via SAML NameID Comment Truncation |
| CVE-2026-73511 | 5.3 | 44.3 | — | Envoy: Potential path-matching/authentication bypass when using Envoy in combination wi… |
| CVE-2026-81378 | 8.2 | 43.5 | — | Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-67201 | 7.7 | 43.1 | — | V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http |
| CVE-2026-49332 | 8.5 | 42.9 | — | Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables ident… |
| CVE-2026-85184 | 9.1 | 42.3 | — | @fastify/middie vulnerable to path-scoped middleware bypass via absolute-form request t… |
| CVE-2026-14198 | 9.1 | 41.9 | — | @fastify/middie vulnerable to authorization bypass via encoded slash in path parameter … |
| CVE-2026-73553 | 7.5 | 41.9 | — | Envoy: RBAC Authorization Bypass via Path Parameters |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| fast-uri | 7 |
| @fastify/middie | 2 |
| envoyproxy | 2 |
| goauthentik | 2 |
| guzzle | 2 |
| jovancoding | 2 |
| kludex | 2 |
| nodemailer | 2 |
| symfony | 2 |
| @fastify/static | 1 |
| apache | 1 |
| benoitc | 1 |
| capgo | 1 |
| cedar-policy | 1 |
| elysiajs | 1 |