CWE-1038: Insecure Automated Optimizations
The product uses a mechanism that automatically optimizes code, e.g. to improve a characteristic such as performance, but the optimizations can have an unintended side effect that might violate an intended security assumption.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-48877 — Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframe
Recently published
- CVE-2025-48877 — Discourse vulnerable to auto-executing of third-party code in embedded CodePen iframe