Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-674 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 114 | 106 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▃█▇▇
2025-09 2 · 2025-10 2 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 4 · 2026-04 2 · 2026-05 9 · 2026-06 33 · 2026-07 29 · 2026-08 29
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-5971 | 7.5 | 84.8 | — | Undertow: response write hangs in case of java 17 tlsv1.3 newsessionticket |
| CVE-2026-41606 | 5.3 | 63.1 | — | Apache Thrift: c_glib dispatch stack overflow |
| CVE-2026-32141 | 7.5 | 54.0 | — | flatted: Unbounded recursion DoS in parse() revive phase |
| CVE-2026-30922 | 7.5 | 53.8 | — | pyasn1 Vulnerable to Denial of Service via Unbounded Recursion |
| CVE-2026-45133 | 8.2 | 51.8 | — | Symfony: [Yaml] Harden the parser when handling untrusted input |
| CVE-2026-42039 | 6.9 | 51.0 | — | Axios: unbounded recursion in toFormData causes DoS via deeply nested request data |
| CVE-2026-25048 | 8.7 | 50.6 | — | xgrammar: Multi-layer nesting causes DoS |
| CVE-2026-49451 | 7.5 | 50.2 | — | Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing |
| CVE-2026-4224 | 6.0 | 47.8 | — | Stack overflow parsing XML with deeply nested DTD content models |
| CVE-2026-58178 | 8.2 | 47.7 | — | Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request… |
| CVE-2026-44289 | 7.5 | 45.1 | — | protobufjs: Denial of service through unbounded protobuf recursion |
| CVE-2026-17177 | 7.5 | 43.6 | — | IBM Db2 Mirror for i is affected by multiple vulnerabilities |
| CVE-2026-61483 | 7.5 | 42.1 | — | Apache Lucy: QueryParser unbounded recursion on deeply-nested query -> C-stack-overflow… |
| CVE-2026-15830 | 6.9 | 42.1 | — | Potential denial-of-service vulnerability via nested geometry collections |
| CVE-2026-66274 | 7.5 | 40.4 | — | Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow |
| CVE-2026-67590 | 7.5 | 40.4 | — | Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow |
| CVE-2026-54297 | 7.5 | 40.0 | — | Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via … |
| CVE-2026-67552 | 7.5 | 39.7 | — | Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stacko… |
| CVE-2026-68073 | 7.5 | 39.7 | — | Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow |
| CVE-2026-32327 | 9.1 | 39.3 | — | Apache Portable Runtime Utility: apr-util XML stack recursion crash |
| Vendor | CVEs |
|---|---|
| linux | 15 |
| apache | 9 |
| elastic | 8 |
| scriban | 5 |
| surrealdb | 5 |
| ibm | 4 |
| imagemagick | 4 |
| messagepack-csharp | 4 |
| protobufjs | 3 |
| axios | 2 |
| busybox | 2 |
| gen digital | 2 |
| hapifhir | 2 |
| legion of the bouncy castle | 2 |
| red hat | 2 |