What is CWE-190?
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-190 is a base-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: Not Language-Specific; Language: C; Technology: Not Technology-Specific.
Source: MITRE CWE (CWE-190 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Availability — DoS: Crash, Exit, or Restart, DoS: Resource Consumption (Memory), DoS: Instability. This weakness can generally lead to undefined behavior and therefore crashes. When the calculated result is used for resource allocation, this weakness can cause too many (or too few) resources to be allocated, possibly enabling crashes if the product requests more resources than can be provided.
- Integrity — Modify Memory. If the value in question is important to data (as opposed to flow), simple data corruption has occurred. Also, if the overflow/wraparound results in other conditions such as buffer overflows, further memory corruption may occur.
- Confidentiality, Availability, Access Control — Execute Unauthorized Code or Commands, Bypass Protection Mechanism. This weakness can sometimes trigger buffer overflows, which can be used to execute arbitrary code. This is usually outside the scope of the product's implicit security policy.
- Availability, Other — Alter Execution Logic, DoS: Crash, Exit, or Restart, DoS: Resource Consumption (CPU). If the overflow/wraparound occurs in a loop index variable, this could cause the loop to terminate at the wrong time - too early, too late, or not at all (i.e., infinite loops). With too many iterations, some loops could consume too many resources such as memory, file handles, etc., possibly leading to a crash or other DoS.
- Access Control — Bypass Protection Mechanism. If integer values are used in security-critical decisions, such as calculating quotas or allocation limits, integer overflows can be used to cause an incorrect security decision.
Source: MITRE CWE, common consequences.
How CWE-190 is exploited in the wild
Threadlinqs maps 37 CVEs to CWE-190, published between 2012-05-17 and 2026-09-25. 5 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 4 critical, 12 high, 16 medium, 2 low. The highest EPSS score in the set is 99.5% (CVE-2020-16040), the modelled probability of exploitation in the next 30 days. 51 tracked threats reference CWE-190 directly or through a CVE it covers; the most recent is “Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40” (2026-09-25). Affected products concentrate in libexpat project (9), Microsoft (4), Apple (3), among 21 vendors in total.
Vulnerabilities (CVEs)
All 37 CVEs mapped to CWE-190, CISA KEV first, then by CVSS score.
- CVE-2023-2136 — CISA KEV · CVSS 9.6 critical · EPSS 0.6% · published 2023-04-19
- CVE-2021-30860 — CISA KEV · CVSS 7.8 high · EPSS 75.9% · published 2021-08-24
- CVE-2023-32434 — CISA KEV · CVSS 7.8 high · EPSS 57.7% · published 2023-06-23
- CVE-2021-30952 — CISA KEV · CVSS 7.8 high · EPSS 1.2% · published 2021-08-24
- CVE-2026-21385 — CISA KEV · CVSS 7.8 high · EPSS 0.2% · published 2026-03-02
- CVE-2026-47291 — CVSS 9.8 critical · EPSS 21.5% · published 2026-06-09
- CVE-2025-54957 — CVSS 9.8 critical · EPSS 1.5% · published 2025-10-20
- CVE-2026-23666 — CVSS 9.8 critical · EPSS 0.1% · published 2026-04-14
- CVE-2026-65423 — CVSS 8.8 high · EPSS 0.6% · published 2026-07-30
- CVE-2026-56711 — CVSS 8.8 high · EPSS 0.2% · published 2026-09-09
- CVE-2026-48095 — CVSS 8.8 high · EPSS 0.0% · published 2026-06-05
- CVE-2026-70329 — CVSS 8.8 high · published 2026-08-11
- CVE-2026-92248 — CVSS 7.8 high · EPSS 0.1% · published 2026-09-15
- CVE-2026-59117 — CVSS 7.5 high · EPSS 0.4% · published 2026-07-16
- CVE-2026-55203 — CVSS 7.5 high · published 2026-06-18
- CVE-2025-66280 — CVSS 7.2 high · EPSS 0.3% · published 2026-06-10
- CVE-2026-56403 — CVSS 6.9 medium · published 2026-06-21
- CVE-2026-56404 — CVSS 6.9 medium · published 2026-06-21
- CVE-2026-56405 — CVSS 6.9 medium · published 2026-06-21
- CVE-2026-56406 — CVSS 6.9 medium · published 2026-06-21
- CVE-2026-56407 — CVSS 6.9 medium · published 2026-06-21
- CVE-2026-56408 — CVSS 6.9 medium · published 2026-06-21
- CVE-2026-56410 — CVSS 6.9 medium · published 2026-06-21
- CVE-2026-56411 — CVSS 6.9 medium · published 2026-06-21
- CVE-2020-16040 — CVSS 6.5 medium · EPSS 99.5% · published 2021-01-08
- CVE-2026-90596 — CVSS 6.5 medium · EPSS 0.3% · published 2026-09-13
- CVE-2025-14181 — CVSS 6.5 medium · published 2026-09-25
- CVE-2026-56409 — CVSS 6.5 medium · published 2026-06-21
- CVE-2012-0038 — CVSS 5.5 medium · EPSS 0.3% · published 2012-05-17
- CVE-2026-92259 — CVSS 5.5 medium · EPSS 0.1% · published 2026-09-15
- CVE-2026-3196 — CVSS 5.5 medium · published 2026-06-19
- CVE-2026-6103 — CVSS 4.3 medium · published 2026-09-25
- CVE-2026-56363 — CVSS 3.3 low · published 2026-06-30
- CVE-2026-16517 — CVSS 2.9 low · EPSS 0.0% · published 2026-07-21
- CVE-2026-45258 — EPSS 0.1% · published 2026-06-27
- CVE-2026-49416 — EPSS 0.1% · published 2026-06-27
- CVE-2026-16174 — EPSS 0.1% · published 2026-09-10
Affected vendors
- libexpat project — 9 CVEs
- Microsoft — 4 CVEs
- Apple — 3 CVEs
- Red Hat — 3 CVEs
- Debian — 2 CVEs
- Fedoraproject — 2 CVEs
- FreeBSD — 2 CVEs
- Google — 2 CVEs
- PHP Group — 2 CVEs
- ImageMagick — 1 CVE
- Linux — 1 CVE
- Netskope — 1 CVE
Threat activity
51 tracked threats cite CWE-190; the 25 most recent are listed.
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage (CVE-2026-91765, CVE-2026-91768, CVE-2026-6103 and 8 Others) — GovCERT.HK A26-09-40MEDIUM
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill)HIGH
- PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)HIGH
- Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)CRITICAL
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read (CVE-2026-73324)HIGH
- Zero-click Pixel 10 exploit chain: VPU driver mmap flaw (CVE-2026-0106) enables arbitrary kernel read/write, chained with Dolby decoder RCE (CVE-2025-54957)CRITICAL
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEsCRITICAL
- Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346, CVE-2026-59347)CRITICAL
- Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six BlockchainsCRITICAL
- Apple Patches ImageIO Integer Overflow (CVE-2026-65346) Exploitable via Malicious ImagesHIGH
- Apple Expands On-Device Lock Screen Alerts for Mercenary Spyware TargetsHIGH
- CVE-2026-70329: Microsoft Outlook Remote Code Execution via Integer OverflowHIGH
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical FlawsCRITICAL
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel buildsHIGH
- Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle FilesHIGH
- NSO Group Co-Founder Shalev Hulio Held Israeli Diplomatic Passport in Panama, Raising State-Ties Questions for Pegasus Spyware Vendor
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation WindowsMEDIUM
- GitLab RCE via Chained Oj JSON Parser Memory-Safety Flaws (Code Execution as 'git' User)HIGH
- Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)HIGH
- CVE-2026-53910: Heap-Based Buffer Overflow in GNU diffutils diff3 (Signed Integer Overflow)MEDIUM
- Pixel 10 VPU Driver mmap Boundary-Check Flaw Enables Root Exploit Chain (CVE-2025-54957)CRITICAL
- CVE-2026-47291: Remote Code Execution in Windows HTTP.sys (Kernel-Mode Integer Overflow)CRITICAL
- Pwn2Own Berlin 2026 Day Three: Zero-Days Demonstrated in VMware ESXi, Microsoft SharePoint, Windows 11, Red Hat Linux, and Anthropic Claude CodeHIGH
- CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code ExecutionHIGH
Mitigations
- Requirements: Ensure that all protocols are strictly defined, such that all out-of-bounds behavior can be identified simply, and require strict conformance to the protocol.
- Requirements / Language Selection: Use a language that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid. If possible, choose a language or compiler that performs automatic bounds checking.
- Architecture and Design / Libraries or Frameworks: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Use libraries or frameworks that make it easier to handle numbers without unexpected consequences. Examples include safe integer handling packages such as SafeInt (C++) or IntegerLib (C or C++). [REF-106]
- Implementation / Input Validation: Perform input validation on any numeric input by ensuring that it is within the expected range. Enforce that the input meets both the minimum and maximum requirements for the expected range. Use unsigned integers where possible. This makes it easier to perform validation for integer overflows. When signed integers are required, ensure that the range check includes minimum values as well as maximum values.
- Implementation: Understand the programming language's underlying representation and how it interacts with numeric calculation (CWE-681). Pay close attention to byte size discrepancies, precision, signed/unsigned distinctions, truncation, conversion and casting between types, "not-a-number" calculations, and how the language handles numbers that are too large or too small for its underlying representation. [REF-7] Also be careful to account for 32-bit, 64-bit, and other potential differences that may affect the numeric representation.
- Architecture and Design: For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
- Implementation / Compilation or Build Hardening: Examine compiler warnings closely and eliminate problems with potential security implications, such as signed / unsigned mismatch in memory operations, or use of uninitialized variables. Even if the weakness is rarely exploitable, a single failure may lead to the compromise of the entire system.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis (effectiveness: High): This weakness can often be detected using automated static analysis tools. Many modern tools use data flow analysis or constraint-based techniques to minimize the number of false positives.
- Black Box (effectiveness: Moderate): Sometimes, evidence of this weakness can be detected using dynamic tools and techniques that interact with the product using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, and fault injection. The product's operation may slow down, but it should not become unstable, crash, or generate incorrect results.
- Manual Analysis (effectiveness: High): This weakness can be detected using tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. Specifically, manual static analysis is useful for evaluating the correctness of allocation calculations. This can be useful for detecting overflow conditions (CWE-190) or similar weaknesses that might have serious security impacts on the program.
- Automated Static Analysis - Binary or Bytecode (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Bytecode Weakness Analysis - including disassembler + source code weakness analysis Binary Weakness Analysis - including disassembler + source code weakness analysis
- Dynamic Analysis with Manual Results Interpretation (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Fuzz Tester Framework-based Fuzzer
- Manual Static Analysis - Source Code (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Manual Source Code Review (not inspections)
- Automated Static Analysis - Source Code (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer
- Architecture or Design Review (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Formal Methods / Correct-By-Construction Cost effective for partial coverage: Inspection (IEEE 1028 standard) (can apply to requirements, design, source code, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.