Cyber Posture

CWE · MITRE source

CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition

Abstraction: Base · CVEs in our corpus: 603

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
AU-8Time StampsAUTimestamps meeting UTC or offset standards help identify TOCTOU issues through precise chronological reconstruction of check/use operations.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-30088 KEV8.87.00.89382024-06-11
CVE-2024-503797.19.80.84982024-12-17
CVE-2023-381466.98.80.86462023-09-12
CVE-2025-22224 KEV6.79.30.47302025-03-04
CVE-2022-35906.65.90.90762022-12-14
CVE-2020-13374.97.80.55312020-08-17
CVE-2004-05944.70.00.77732004-07-27
CVE-2023-35311 KEV3.88.80.00472023-07-11
CVE-2025-38352 KEV3.57.40.00102025-07-22
CVE-2022-48618 KEV3.47.00.00172024-01-09
CVE-2003-08133.20.00.53442003-11-17
CVE-2019-08363.07.80.24822019-04-09
CVE-2024-262182.97.80.21892024-04-09
CVE-2024-563372.69.80.10172024-12-20
CVE-2021-327082.49.80.07332021-06-24
CVE-2024-483222.48.10.13642024-11-11
CVE-2021-428352.37.00.14202021-12-08
CVE-2022-369802.38.10.11812023-03-29
CVE-2019-72492.09.80.01472019-01-31
CVE-2019-54212.09.80.00232019-04-03
CVE-2024-287182.09.80.01182024-04-12
CVE-2024-271142.09.80.01062024-09-11
CVE-2024-01322.09.00.03912024-09-26
CVE-2024-417792.09.80.00032024-11-22
CVE-2024-417872.09.80.00022025-01-10