CWE-50 · 2 records
Path Equivalence: '//multiple/leading/slash'
CVEs in this class
2 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2026-66835No exploit | httpd mod_auth directory protection bypassed by a doubled slash in the request patherlang · otp · CWE-50 | High8.2 | — | 1.0% | Sep 1, 2026 |
31Monitor | CVE-2023-34092Proof of concept | Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)vitejs · vite · CWE-50 | High7.5 | — | 3.1% | Jun 1, 2023 |
- CVE-2026-6683532Monitor
httpd mod_auth directory protection bypassed by a doubled slash in the request path
HighCVSS 8.2No exploitEPSS 1%erlang · otpSep 1, 2026
- CVE-2023-3409231Monitor
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
HighCVSS 7.5Proof of conceptEPSS 3%vitejs · viteJun 1, 2023