CWE-1086: Class with Excessive Number of Child Classes
A class contains an unnecessarily large number of children.
Last updated
A class contains an unnecessarily large number of children.
Last updated
While the interpretation of "large number of children" may vary for each product or developer, CISQ recommends a default maximum of 10 child classes.
What can happen when CWE-1086 is exploited.
Reduce Maintainability, Increase Analytical Complexity
Affects: Other
This issue makes it more difficult to understand and maintain the software, which indirectly affects security by making it more difficult or time-consuming to find and/or fix vulnerabilities. It also might make it easier to introduce vulnerabilities.
Typically introduced during these phases of the software lifecycle.
Languages
Common questions about CWE-1086.
A class contains an unnecessarily large number of children.
Exploiting CWE-1086 can lead to: Reduce Maintainability, Increase Analytical Complexity.
Weakness data is sourced from the MITRE CWE catalog (v4.20). CVE associations are aggregated and kept current by RadicalNotion.AI.
Get alerted the moment a new CWE-1086 vulnerability affects your stack, with AI-written analysis, severity context, and remediation guidance.