Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-444
Weakness type CWE-444 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 130 | 123 | 5 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▄▅▄█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 5 · 2026-04 3 · 2026-05 8 · 2026-06 20 · 2026-07 22 · 2026-08 20 · 2026-09 44 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2022-22536 | 9.8 | 99.9 | KEV | SAP Multiple Products |
| CVE-2025-61884 | 7.5 | 99.9 | KEV | Oracle E-Business Suite |
| CVE-2023-41265 | 9.9 | 99.8 | KEV | Qlik Sense |
| CVE-2023-48365 | 9.6 | 98.8 | KEV | Qlik Sense |
| CVE-2026-48710 | 6.5 | 94.0 | KEV | Starlette has missing Host header validation that poisons request.url.path, bypassing p… |
| CVE-2026-93569 | 8.2 | 71.8 | — | Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 … |
| CVE-2026-93574 | 6.5 | 70.7 | — | Io.netty/netty-codec-http: netty: http request smuggling via post-digit whitespace in c… |
| CVE-2026-40175 | 4.8 | 69.6 | — | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| CVE-2026-2332 | 9.1 | 69.5 | — | HTTP Request Smuggling via Chunked Extension Quoted-String Parsing |
| CVE-2026-48746 | 9.1 | 65.8 | — | vLLM: OpenAI auth bypass |
| CVE-2026-14180 | 5.3 | 62.6 | — | Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap |
| CVE-2026-93573 | 6.5 | 58.2 | — | Io.netty/netty-codec-http: netty split transfer-encoding fields bypass final-chunked va… |
| CVE-2026-28367 | 9.1 | 57.9 | — | Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator |
| CVE-2026-28368 | 9.1 | 57.9 | — | Undertow: undertow: request smuggling via inconsistent header parsing |
| CVE-2026-28369 | 9.1 | 57.9 | — | Undertow: undertow: request smuggling via malformed http request headers |
| CVE-2024-12397 | 7.4 | 56.1 | — | Io.quarkus.http/quarkus-http-core: quarkus http cookie smuggling |
| CVE-2026-63382 | 9.2 | 54.5 | — | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling |
| CVE-2026-62899 | 5.9 | 53.3 | — | .NET Security Feature Bypass Vulnerability |
| CVE-2026-31842 | 8.7 | 53.1 | — | Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding h… |
| CVE-2026-9190 | 9.1 | 52.9 | — | HTTP request smuggling in Progress MarkLogic Server |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| ibm | 13 |
| red hat | 12 |
| apache | 9 |
| netty | 9 |
| http4s | 6 |
| elixir-mint | 4 |
| erlang | 4 |
| eclipse foundation | 3 |
| libevent | 3 |
| traefik | 3 |
| apple | 2 |
| aws | 2 |
| cesanta | 2 |
| envoyproxy | 2 |
| honojs | 2 |