boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-674

Weakness type CWE-674 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1141060

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃█▇▇

2025-09 2 · 2025-10 2 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 4 · 2026-04 2 · 2026-05 9 · 2026-06 33 · 2026-07 29 · 2026-08 29

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2024-59717.584.8Undertow: response write hangs in case of java 17 tlsv1.3 newsessionticket
CVE-2026-416065.363.1Apache Thrift: c_glib dispatch stack overflow
CVE-2026-321417.554.0flatted: Unbounded recursion DoS in parse() revive phase
CVE-2026-309227.553.8pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-451338.251.8Symfony: [Yaml] Harden the parser when handling untrusted input
CVE-2026-420396.951.0Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
CVE-2026-250488.750.6xgrammar: Multi-layer nesting causes DoS
CVE-2026-494517.550.2Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing
CVE-2026-42246.047.8Stack overflow parsing XML with deeply nested DTD content models
CVE-2026-581788.247.7Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request…
CVE-2026-442897.545.1protobufjs: Denial of service through unbounded protobuf recursion
CVE-2026-171777.543.6IBM Db2 Mirror for i is affected by multiple vulnerabilities
CVE-2026-614837.542.1Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow…
CVE-2026-158306.942.1Potential denial-of-service vulnerability via nested geometry collections
CVE-2026-662747.540.4Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow
CVE-2026-675907.540.4Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
CVE-2026-542977.540.0Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via …
CVE-2026-675527.539.7Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stacko…
CVE-2026-680737.539.7Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
CVE-2026-323279.139.3Apache Portable Runtime Utility: apr-util XML stack recursion crash

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
linux15
apache9
elastic8
scriban5
surrealdb5
ibm4
imagemagick4
messagepack-csharp4
protobufjs3
axios2
busybox2
gen digital2
hapifhir2
legion of the bouncy castle2
red hat2