Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-444 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 72 | 67 | 2 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▂▄▇█▅
2025-09 1 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 3 · 2026-04 3 · 2026-05 8 · 2026-06 20 · 2026-07 22 · 2026-08 11
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2023-41265 | 9.9 | 99.7 | KEV | Qlik Sense |
| CVE-2026-40175 | 4.8 | 77.8 | — | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| CVE-2026-48710 | 6.5 | 77.3 | — | Starlette has missing Host header validation that poisons request.url.path, bypassing p… |
| CVE-2026-2332 | 9.1 | 66.1 | — | HTTP Request Smuggling via Chunked Extension Quoted-String Parsing |
| CVE-2026-48746 | 9.1 | 64.4 | — | vLLM: OpenAI auth bypass |
| CVE-2026-6324 | 4.8 | 56.1 | — | Libsoup: libsoup: http request smuggling via unsigned to signed conversion error |
| CVE-2024-12397 | 7.4 | 53.6 | — | Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling |
| CVE-2026-42584 | 9.1 | 53.1 | — | Netty: HttpClientCodec response desynchronization |
| CVE-2026-62899 | 5.9 | 50.6 | — | .NET Security Feature Bypass Vulnerability |
| CVE-2026-27690 | 9.1 | 49.9 | — | HTTP Request Smuggling in SAP Approuter |
| CVE-2026-28369 | 9.1 | 49.5 | — | Undertow: undertow: request smuggling via malformed http request headers |
| CVE-2026-33870 | 7.5 | 47.9 | — | Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing |
| CVE-2026-42581 | 9.8 | 47.5 | — | Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization |
| CVE-2026-31842 | 8.7 | 44.9 | — | Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding h… |
| CVE-2026-71324 | 7.0 | 43.7 | — | Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend … |
| CVE-2026-23941 | 7.0 | 42.5 | — | Request smuggling via first-wins Content-Length parsing in inets httpd |
| CVE-2026-58047 | 5.6 | 41.9 | — | — |
| CVE-2026-39805 | 6.3 | 41.9 | — | CL.CL HTTP request smuggling via duplicate Content-Length in bandit |
| CVE-2026-13763 | 7.9 | 39.1 | — | HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer … |
| Vendor | CVEs |
|---|---|
| ibm | 7 |
| netty | 6 |
| red hat | 6 |
| apache | 5 |
| apple | 2 |
| aws | 2 |
| eclipse foundation | 2 |
| elixir-mint | 2 |
| kludex | 2 |
| tinyproxy | 2 |
| tomaka | 2 |
| actix | 1 |
| aio-libs | 1 |
| axios | 1 |
| caddyserver | 1 |