Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-789
Weakness type CWE-789 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 132 | 130 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▃▄▆▇█▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 9 · 2026-06 14 · 2026-07 26 · 2026-08 33 · 2026-09 37 · 2026-10 10
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-49975 | 7.5 | 90.6 | — | Apache HTTP Server: mod_http2 denial of service |
| CVE-2024-43484 | 7.5 | 86.7 | — | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability |
| CVE-2026-66733 | 8.7 | 74.3 | — | Sonic 3 A.I.R. Unbounded Memory Allocation DoS via ReceivedPacketCache |
| CVE-2026-43868 | 5.3 | 67.1 | — | Apache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern |
| CVE-2026-40378 | 7.5 | 66.4 | — | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability |
| CVE-2026-42440 | 7.5 | 63.5 | — | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader |
| CVE-2026-42154 | 7.5 | 58.1 | — | Prometheus: remote read endpoint allows denial of service via crafted snappy payload |
| CVE-2026-65315 | 8.7 | 55.4 | — | Ollama Remote Denial of Service via Attacker-Controlled Allocation in GGUF Metadata Parser |
| CVE-2026-66273 | 7.5 | 54.2 | — | Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-aut… |
| CVE-2026-67551 | 7.5 | 54.2 | — | Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pr… |
| CVE-2026-67589 | 7.5 | 54.2 | — | Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-aut… |
| CVE-2026-85442 | 8.7 | 53.9 | — | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation |
| CVE-2026-55407 | 6.3 | 53.5 | — | Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Alloca… |
| CVE-2026-91752 | 8.7 | 53.0 | — | GNU libextractor before 1.15 Stack Overflow via OLE2 |
| CVE-2026-50734 | 7.5 | 53.0 | — | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWi… |
| CVE-2026-53916 | 7.5 | 53.0 | — | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in… |
| CVE-2026-53917 | 7.5 | 53.0 | — | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: U… |
| CVE-2026-67211 | 7.5 | 53.0 | — | Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer |
| CVE-2026-69219 | 8.7 | 52.5 | — | RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via un… |
| CVE-2026-55149 | 7.5 | 52.2 | — | Vouch Proxy: Unbounded Multipart Cookie Allocation DoS |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 23 |
| legion of the bouncy castle | 9 |
| elastic | 5 |
| python-pillow | 5 |
| red hat | 3 |
| cisco | 2 |
| eclipse foundation | 2 |
| emiago | 2 |
| envoyproxy | 2 |
| gnu | 2 |
| h2o | 2 |
| jahlives | 2 |
| m2team | 2 |
| mattermost | 2 |
| microsoft | 2 |