Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-834
Weakness type CWE-834 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 17 | 16 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▂▄█▂
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 2 · 2026-07 1 · 2026-08 3 · 2026-09 8 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-64641 | 8.2 | 57.0 | — | Next.js: Denial of Service in App Router using Server Actions |
| CVE-2026-77357 | 8.7 | 42.9 | — | Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker th… |
| CVE-2026-59644 | 8.7 | 40.3 | — | MLS hash-ratchet honours arbitrary 32-bit generation counter from sender |
| CVE-2026-45680 | 7.5 | 39.4 | — | OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU |
| CVE-2026-16497 | 7.5 | 38.9 | — | — |
| CVE-2026-91137 | 8.7 | 34.7 | — | Apache Thrift: PHP `thrift_protocol` accelerator: zero-byte container elements |
| CVE-2026-81872 | 6.3 | 30.1 | — | OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full |
| CVE-2026-53493 | 6.9 | 27.2 | — | Containerd has image-pull DoS via crafted OCI index graph amplification |
| CVE-2026-87721 | 8.7 | 23.1 | — | Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit C… |
| CVE-2026-77399 | 6.5 | 22.0 | — | icalendar: Denial of service via unbounded VALARM REPEAT expansion |
| CVE-2026-50171 | 8.2 | 15.7 | — | Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) |
| CVE-2024-42071 | 5.5 | 11.0 | — | ionic: use dev_consume_skb_any outside of napi |
| CVE-2026-48156 | 5.1 | 6.0 | — | pypdf: Possible long runtimes for zero-only width values in cross-reference streams |
| CVE-2026-81880 | 5.5 | 2.8 | — | radare2: Uncontrolled resource consumption in radare2 PEF loader |
| CVE-2026-84310 | 4.8 | 2.5 | — | pypdf: Possible long runtimes/large memory usage when retrieving outlines |
| CVE-2026-84311 | 4.8 | 2.5 | — | pypdf: Possible long runtimes/large memory usage when extracting XForm objects |
| CVE-2026-71852 | 4.8 | 2.0 | — | pypdf: Possible long runtimes/large memory usage for large CID font width ranges |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| py-pdf | 4 |
| open-telemetry | 2 |
| angular | 1 |
| apache | 1 |
| collective | 1 |
| containerd | 1 |
| gerrit | 1 |
| legion of the bouncy castle | 1 |
| linux | 1 |
| mesop-dev | 1 |
| nvidia | 1 |
| radareorg | 1 |
| vercel | 1 |