CWE-177 · 16 записей
Improper Handling of URL Encoding (Hex Encoding)
CVE этого класса
16 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-29045Эксплойта нет | Hono: Arbitrary file access via serveStatic vulnerabilityhono · hono · CWE-177 | Критическая9,8 | — | 0,6 % | 4 мар. 2026 г. |
36Наблюдать | CVE-2026-41041Эксплойта нет | Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintendedapache · gravitino · CWE-177 | Критическая9,1 | — | 0,6 % | 13 июл. 2026 г. |
36Наблюдать | CVE-2026-59083Эксплойта нет | Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypassapache · tomcat · CWE-177 | Критическая9,1 | — | 0,4 % | 14 июл. 2026 г. |
35Наблюдать | CVE-2026-22031Эксплойта нет | Fastify Middie Middleware Path Bypassfastify · fastify\/middie · CWE-177 | Высокая8,8 | — | 0,5 % | 19 янв. 2026 г. |
33Наблюдать | CVE-2026-22037Эксплойта нет | @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)fastify · fastify-express · CWE-177 | Высокая8,4 | — | 0,4 % | 19 янв. 2026 г. |
33Наблюдать | CVE-2026-96748Эксплойта нет | Connection redirection via percent-encoded delimiter injection in connection string hostsmongodb · python driver · CWE-177 | Высокая8,3 | — | 0,3 % | 5 дней назад |
32Наблюдать | CVE-2026-15371Эксплойта нет | Velociraptor Stored XSS in URL column typesrapid7 · velociraptor · CWE-177 | Высокая8,1 | — | 0,4 % | 18 авг. 2026 г. |
32Наблюдать | GHSA-wm77-q74p-5763Эксплойта нет | Path Traversal in superstaticnpm · superstatic · CWE-177 | Высокая8,0 | — | — | 27 июл. 2018 г. |
31Наблюдать | CVE-2022-27780Эксплойта нет | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *differenthaxx · curl · CWE-177 | Высокая7,5 | — | 2,5 % | 2 июн. 2022 г. |
30Наблюдать | CVE-2026-76172Эксплойта нет | fast-uri vulnerable to host confusion via percent-encoded scheme normalizationopenjsf · fast-uri · CWE-177 | Высокая7,5 | — | 0,4 % | 24 авг. 2026 г. |
26Наблюдать | CVE-2022-3854Эксплойта нет | A flaw was found in Ceph, relating to the URL processing on RGW backends.redhat · ceph storage · CWE-177 | Средняя6,5 | — | 0,6 % | 6 мар. 2023 г. |
26Наблюдать | CVE-2026-67448Эксплойта нет | Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)axllent · mailpit · CWE-177 | Средняя6,5 | — | 0,2 % | 20 авг. 2026 г. |
23Наблюдать | CVE-2026-6414Эксплойта нет | @fastify/static vulnerable to route guard bypass via encoded path separatorsfastify · fastify-static · CWE-177 | Средняя5,9 | — | 0,4 % | 16 апр. 2026 г. |
21Наблюдать | CVE-2018-3718Эксплойта нет | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.zeit · serve · CWE-177 | Средняя5,3 | — | 1,3 % | 6 июн. 2018 г. |
14Наблюдать | CVE-2025-11990Эксплойта нет | Improper Handling of URL Encoding (Hex Encoding) in GitLabgitlab · gitlab · CWE-177 | Низкая3,5 | — | 0,3 % | 15 нояб. 2025 г. |
9Наблюдать | CVE-2024-48866Эксплойта нет | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions.qnap · qts · CWE-177 | Низкая2,3 | — | 0,4 % | 6 дек. 2024 г. |
- CVE-2026-2904539Наблюдать
Hono: Arbitrary file access via serveStatic vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hono · hono4 мар. 2026 г.
- CVE-2026-4104136Наблюдать
Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %apache · gravitino13 июл. 2026 г.
- CVE-2026-5908336Наблюдать
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %apache · tomcat14 июл. 2026 г.
- CVE-2026-2203135Наблюдать
Fastify Middie Middleware Path Bypass
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fastify · fastify\/middie19 янв. 2026 г.
- CVE-2026-2203733Наблюдать
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %fastify · fastify-express19 янв. 2026 г.
- CVE-2026-9674833Наблюдать
Connection redirection via percent-encoded delimiter injection in connection string hosts
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %mongodb · python driver5 дней назад
- CVE-2026-1537132Наблюдать
Velociraptor Stored XSS in URL column types
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %rapid7 · velociraptor18 авг. 2026 г.
- GHSA-wm77-q74p-576332Наблюдать
Path Traversal in superstatic
ВысокаяCVSS 8,0Эксплойта нетnpm · superstatic27 июл. 2018 г.
- CVE-2022-2778031Наблюдать
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %haxx · curl2 июн. 2022 г.
- CVE-2026-7617230Наблюдать
fast-uri vulnerable to host confusion via percent-encoded scheme normalization
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %openjsf · fast-uri24 авг. 2026 г.
- CVE-2022-385426Наблюдать
A flaw was found in Ceph, relating to the URL processing on RGW backends.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %redhat · ceph storage6 мар. 2023 г.
- CVE-2026-6744826Наблюдать
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
СредняяCVSS 6,5Эксплойта нетEPSS 0 %axllent · mailpit20 авг. 2026 г.
- CVE-2026-641423Наблюдать
@fastify/static vulnerable to route guard bypass via encoded path separators
СредняяCVSS 5,9Эксплойта нетEPSS 0 %fastify · fastify-static16 апр. 2026 г.
- CVE-2018-371821Наблюдать
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %zeit · serve6 июн. 2018 г.
- CVE-2025-1199014Наблюдать
Improper Handling of URL Encoding (Hex Encoding) in GitLab
НизкаяCVSS 3,5Эксплойта нетEPSS 0 %gitlab · gitlab15 нояб. 2025 г.
- CVE-2024-488669Наблюдать
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions.
НизкаяCVSS 2,3Эксплойта нетEPSS 0 %qnap · qts6 дек. 2024 г.