CWE · MITRE source
CWE-99Improper Control of Resource Identifiers ('Resource Injection')
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.
A resource injection issue occurs when the following two conditions are met: This may enable an attacker to access or modify otherwise protected system resources.
Last updated: 22 August 2026 14:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): CAPEC 1 (partial)
OWASP Top 10 for Web (2025)
This weakness contributes to A05:2025 Injection.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2017-5159 UPD | 7.7 | 9.8 | 0.0243 | 2017-02-13 |
CVE-2021-22879 UPD | 7.2 | 8.8 | 0.0470 | 2021-04-14 |
CVE-2025-43491 UPD | 7.2 | 9.8 | 0.0028 | 2025-09-09 |
CVE-2019-6545 UPD | 6.9 | 7.5 | 0.1386 | 2019-02-13 |
CVE-2024-5706 UPD | 6.7 | 8.8 | 0.0072 | 2025-02-19 |
CVE-2025-0756 UPD | 6.6 | 9.1 | 0.0091 | 2025-04-16 |
CVE-2024-57971 UPD | 6.5 | 9.1 | 0.0071 | 2025-02-16 |
CVE-2025-2410 UPD | 6.4 | 9.1 | 0.0047 | 2025-05-22 |
CVE-2022-39369 UPD | 6.3 | 8.0 | 0.0109 | 2022-11-01 |
CVE-2023-3517 UPD | 6.2 | 8.5 | 0.0064 | 2023-12-12 |
CVE-2020-8177 UPD | 6.1 | 7.8 | 0.0124 | 2020-12-14 |
CVE-2021-42360 UPD | 5.9 | 7.6 | 0.0059 | 2021-11-17 |
CVE-2020-5230 UPD | 5.8 | 7.7 | 0.0117 | 2020-01-30 |
CVE-2026-3693 UPD | 5.7 | 7.3 | 0.0040 | 2026-03-08 |
CVE-2026-62910 | 5.5 | 7.2 | 0.0068 | 2026-08-11 |
CVE-2022-1287 UPD | 5.3 | 6.5 | 0.0072 | 2022-04-09 |
CVE-2022-27670 UPD | 5.3 | 6.5 | 0.0094 | 2022-04-12 |
CVE-2023-6605 UPD | 5.3 | 7.2 | 0.0028 | 2025-01-06 |
CVE-2023-2980 UPD | 5.2 | 6.3 | 0.0112 | 2023-05-30 |
CVE-2016-8615 UPD | 5.1 | 5.3 | 0.0476 | 2018-08-01 |
CVE-2020-6245 UPD | 5.1 | 6.7 | 0.0034 | 2020-05-12 |
CVE-2024-4294 UPD | 5.1 | 6.3 | 0.0086 | 2024-04-27 |
CVE-2024-4817 UPD | 5.1 | 6.3 | 0.0092 | 2024-05-14 |
CVE-2026-33603 UPD | 5.1 | 6.8 | 0.0022 | 2026-05-12 |
CVE-2025-1645 UPD | 5.0 | 6.3 | 0.0042 | 2025-02-25 |