Cyber Resilience

CWE · MITRE source

CWE-99Improper Control of Resource Identifiers ('Resource Injection')

Abstraction: Class · CVEs in our corpus: 58

The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.

A resource injection issue occurs when the following two conditions are met: This may enable an attacker to access or modify otherwise protected system resources.

Last updated: 22 August 2026 14:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 1 mapping(s) from 1 framework(s): CAPEC 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A05:2025 Injection.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AA-05
  • PR.PS-06
  • AC-3 Access Enforcement
  • AC-4 Information Flow Enforcement
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.3.8
  • V1.3.9
  • V1.3.11
  • V9.2.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2017-5159 7.79.80.02432017-02-13
CVE-2021-22879 7.28.80.04702021-04-14
CVE-2025-43491 7.29.80.00282025-09-09
CVE-2019-6545 6.97.50.13862019-02-13
CVE-2024-5706 6.78.80.00722025-02-19
CVE-2025-0756 6.69.10.00912025-04-16
CVE-2024-57971 6.59.10.00712025-02-16
CVE-2025-2410 6.49.10.00472025-05-22
CVE-2022-39369 6.38.00.01092022-11-01
CVE-2023-3517 6.28.50.00642023-12-12
CVE-2020-8177 6.17.80.01242020-12-14
CVE-2021-42360 5.97.60.00592021-11-17
CVE-2020-5230 5.87.70.01172020-01-30
CVE-2026-3693 5.77.30.00402026-03-08
CVE-2026-629105.57.20.00682026-08-11
CVE-2022-1287 5.36.50.00722022-04-09
CVE-2022-27670 5.36.50.00942022-04-12
CVE-2023-6605 5.37.20.00282025-01-06
CVE-2023-2980 5.26.30.01122023-05-30
CVE-2016-8615 5.15.30.04762018-08-01
CVE-2020-6245 5.16.70.00342020-05-12
CVE-2024-4294 5.16.30.00862024-04-27
CVE-2024-4817 5.16.30.00922024-05-14
CVE-2026-33603 5.16.80.00222026-05-12
CVE-2025-1645 5.06.30.00422025-02-25