Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-776
Weakness type CWE-776 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 19 | 19 | 0 |
Monthly trend
▂▂▁▂▇▇▅█▁
2026-02 1 · 2026-03 1 · 2026-04 0 · 2026-05 1 · 2026-06 4 · 2026-07 4 · 2026-08 3 · 2026-09 5 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-26278 | 7.5 | 60.5 | — | fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit) |
| CVE-2026-29074 | 7.5 | 60.5 | — | SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs) |
| CVE-2026-41673 | 8.7 | 57.7 | — | xmldom: Denial of service via uncontrolled recursion in XML serialization |
| CVE-2026-45304 | 8.7 | 50.9 | — | Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expan… |
| CVE-2026-45133 | 8.2 | 48.4 | — | Symfony: [Yaml] Harden the parser when handling untrusted input |
| CVE-2026-44020 | 7.5 | 46.9 | — | Docling: Unsafe XML Entity Expansion in USPTO Patent Backend |
| CVE-2026-14979 | 7.5 | 44.0 | — | IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expa… |
| CVE-2026-78681 | 8.7 | 42.2 | — | NLTK before 3.10.3 Entity Expansion DoS via ElementTree |
| CVE-2026-12993 | 6.5 | 42.1 | — | Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service v… |
| CVE-2026-73569 | 8.7 | 41.1 | — | fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits |
| CVE-2026-45771 | 7.5 | 39.8 | — | Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion |
| CVE-2026-3415 | 8.7 | 39.7 | — | XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products All… |
| CVE-2026-54077 | 7.1 | 36.6 | — | ArcadeDB: IMPORT DATABASE allows SSRF and arbitrary local file read by authenticated users |
| CVE-2026-14865 | 5.3 | 35.3 | — | XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX |
| CVE-2023-46035 | 5.9 | 27.9 | — | — |
| CVE-2026-92001 | 6.1 | 26.3 | — | Apache Sling XSS: Missing parser resource limits |
| CVE-2026-58234 | 2.2 | 24.9 | — | Denial of Service vulnerability in SAP Process Integration (SOAP Adapter) |
| CVE-2026-16180 | 5.7 | 11.9 | — | IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerabl… |
| CVE-2026-44018 | 7.1 | 4.7 | — | Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| docling-project | 2 |
| ibm | 2 |
| naturalintelligence | 2 |
| symfony | 2 |
| apache | 1 |
| arcadedata | 1 |
| com.arcadedb | 1 |
| fnando | 1 |
| nltk | 1 |
| progress | 1 |
| red hat | 1 |
| sap_se | 1 |
| signalwire | 1 |
| svg | 1 |
| wso2 | 1 |