Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-488
Weakness type CWE-488 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 20 | 19 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▅▂▇▃█▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 1 · 2026-07 5 · 2026-08 2 · 2026-09 6 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-86492 | 8.5 | 58.3 | — | — |
| CVE-2026-80231 | 7.5 | 58.2 | — | native CA store conn reuse |
| CVE-2025-1247 | 8.3 | 54.7 | — | Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared … |
| CVE-2026-19931 | 9.8 | 53.3 | — | Negotiate ambient user conn reuse |
| CVE-2026-5773 | 7.5 | 49.7 | — | wrong reuse of SMB connection |
| CVE-2026-16326 | 10.0 | 43.3 | — | consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP statel… |
| CVE-2026-16498 | 10.0 | 37.4 | — | terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP sta… |
| CVE-2026-46416 | 6.3 | 37.2 | — | Microsoft UFO shared WebSocket handler state causes cross-client response hijacking |
| CVE-2026-82806 | 5.3 | 31.6 | — | Apache APISIX: cross-request permission pollution via static permission list mutation |
| CVE-2026-82367 | 2.3 | 31.3 | — | Re-entrant synchronous publish in AshGraphql subscription batcher delivers one subscrib… |
| CVE-2026-54311 | 6.0 | 30.9 | — | n8n: Merge Node SQL Mode Prototype Pollution |
| CVE-2026-8458 | 6.5 | 28.8 | — | wrong reuse for different services |
| CVE-2026-14621 | 1.3 | 28.1 | — | FederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.… |
| CVE-2026-54497 | 6.8 | 23.8 | — | view_component: Reused Component Instances Retain Stale Render Context |
| CVE-2026-84685 | 6.5 | 18.9 | — | Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Manage… |
| CVE-2026-71850 | 4.8 | 17.1 | — | Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure |
| CVE-2026-18489 | 7.4 | 15.8 | — | IBM ContextForge Translate is affected by cross-client credential context confusion |
| CVE-2026-9831 | 6.3 | 15.8 | — | ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race… |
| CVE-2026-88017 | 7.3 | 13.0 | — | rclone: FTP cross-session auth-proxy backend confusion |
| CVE-2026-103544 | 2.1 | 12.4 | — | datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong… |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| curl | 4 |
| hashicorp | 2 |
| apache | 1 |
| ash-project | 1 |
| auth0 | 1 |
| datadrivenconstruction | 1 |
| extreme networks | 1 |
| federatedai | 1 |
| honojs | 1 |
| ibm | 1 |
| jetbrains | 1 |
| microsoft | 1 |
| n8n-io | 1 |
| rclone | 1 |
| red hat | 1 |