CWE-1104: Use of Unmaintained Third Party Components
The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.
Last updated
Overview
CWE-1104 (Use of Unmaintained Third Party Components) is a base-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
22 recorded CVEs are caused by CWE-1104 (Use of Unmaintained Third Party Components). The highest-severity and most recent are shown first. 11 new CWE-1104 CVEs have been recorded so far in 2026 (6 in 2025).
- CVE-2025-12104
Incorrect Content-Type Header
Critical · CVSS 10.0 · EPSS 31th2025-10-23 - CVE-2026-16634
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
Critical · CVSS 9.8 · EPSS 42th2026-07-24 - CVE-2026-3031
Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library
Critical · CVSS 9.8 · EPSS 51th