İçeriğe atla
Noroxi

CWE-177 · 16 kayıt

Improper Handling of URL Encoding (Hex Encoding)

Bu sınıftaki CVE’ler

16 kayıt

  • CVE-2026-29045
    39İzleyin

    Hono: Arbitrary file access via serveStatic vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    hono · hono4 Mar 2026

  • CVE-2026-41041
    36İzleyin

    Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended

    KritikCVSS 9,1İstismar yokEPSS %1

    apache · gravitino13 Tem 2026

  • CVE-2026-59083
    36İzleyin

    Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass

    KritikCVSS 9,1İstismar yokEPSS %0

    apache · tomcat14 Tem 2026

  • CVE-2026-22031
    35İzleyin

    Fastify Middie Middleware Path Bypass

    YüksekCVSS 8,8İstismar yokEPSS %1

    fastify · fastify\/middie19 Oca 2026

  • CVE-2026-22037
    33İzleyin

    @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)

    YüksekCVSS 8,4İstismar yokEPSS %0

    fastify · fastify-express19 Oca 2026

  • CVE-2026-96748
    33İzleyin

    Connection redirection via percent-encoded delimiter injection in connection string hosts

    YüksekCVSS 8,3İstismar yokEPSS %0

    mongodb · python driver5 gün önce

  • CVE-2026-15371
    32İzleyin

    Velociraptor Stored XSS in URL column types

    YüksekCVSS 8,1İstismar yokEPSS %0

    rapid7 · velociraptor18 Ağu 2026

  • Path Traversal in superstatic

    YüksekCVSS 8,0İstismar yok

    npm · superstatic27 Tem 2018

  • CVE-2022-27780
    31İzleyin

    The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different

    YüksekCVSS 7,5İstismar yokEPSS %2

    haxx · curl2 Haz 2022

  • CVE-2026-76172
    30İzleyin

    fast-uri vulnerable to host confusion via percent-encoded scheme normalization

    YüksekCVSS 7,5İstismar yokEPSS %0

    openjsf · fast-uri24 Ağu 2026

  • CVE-2022-3854
    26İzleyin

    A flaw was found in Ceph, relating to the URL processing on RGW backends.

    OrtaCVSS 6,5İstismar yokEPSS %1

    redhat · ceph storage6 Mar 2023

  • CVE-2026-67448
    26İzleyin

    Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

    OrtaCVSS 6,5İstismar yokEPSS %0

    axllent · mailpit20 Ağu 2026

  • CVE-2026-6414
    23İzleyin

    @fastify/static vulnerable to route guard bypass via encoded path separators

    OrtaCVSS 5,9İstismar yokEPSS %0

    fastify · fastify-static16 Nis 2026

  • CVE-2018-3718
    21İzleyin

    serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

    OrtaCVSS 5,3İstismar yokEPSS %1

    zeit · serve6 Haz 2018

  • CVE-2025-11990
    14İzleyin

    Improper Handling of URL Encoding (Hex Encoding) in GitLab

    DüşükCVSS 3,5İstismar yokEPSS %0

    gitlab · gitlab15 Kas 2025

  • An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions.

    DüşükCVSS 2,3İstismar yokEPSS %0

    qnap · qts6 Ara 2024

Tüm zafiyet sınıfları