Перейти к содержимому
Noroxi

CWE-177 · 16 записей

Improper Handling of URL Encoding (Hex Encoding)

CVE этого класса

16 записей

  • CVE-2026-29045
    39Наблюдать

    Hono: Arbitrary file access via serveStatic vulnerability

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    hono · hono4 мар. 2026 г.

  • CVE-2026-41041
    36Наблюдать

    Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    apache · gravitino13 июл. 2026 г.

  • CVE-2026-59083
    36Наблюдать

    Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    apache · tomcat14 июл. 2026 г.

  • CVE-2026-22031
    35Наблюдать

    Fastify Middie Middleware Path Bypass

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    fastify · fastify\/middie19 янв. 2026 г.

  • CVE-2026-22037
    33Наблюдать

    @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    fastify · fastify-express19 янв. 2026 г.

  • CVE-2026-96748
    33Наблюдать

    Connection redirection via percent-encoded delimiter injection in connection string hosts

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    mongodb · python driver5 дней назад

  • CVE-2026-15371
    32Наблюдать

    Velociraptor Stored XSS in URL column types

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    rapid7 · velociraptor18 авг. 2026 г.

  • GHSA-wm77-q74p-5763
    32Наблюдать

    Path Traversal in superstatic

    ВысокаяCVSS 8,0Эксплойта нет

    npm · superstatic27 июл. 2018 г.

  • CVE-2022-27780
    31Наблюдать

    The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    haxx · curl2 июн. 2022 г.

  • CVE-2026-76172
    30Наблюдать

    fast-uri vulnerable to host confusion via percent-encoded scheme normalization

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    openjsf · fast-uri24 авг. 2026 г.

  • CVE-2022-3854
    26Наблюдать

    A flaw was found in Ceph, relating to the URL processing on RGW backends.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    redhat · ceph storage6 мар. 2023 г.

  • CVE-2026-67448
    26Наблюдать

    Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    axllent · mailpit20 авг. 2026 г.

  • CVE-2026-6414
    23Наблюдать

    @fastify/static vulnerable to route guard bypass via encoded path separators

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    fastify · fastify-static16 апр. 2026 г.

  • CVE-2018-3718
    21Наблюдать

    serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    zeit · serve6 июн. 2018 г.

  • CVE-2025-11990
    14Наблюдать

    Improper Handling of URL Encoding (Hex Encoding) in GitLab

    НизкаяCVSS 3,5Эксплойта нетEPSS 0 %

    gitlab · gitlab15 нояб. 2025 г.

  • CVE-2024-48866
    9Наблюдать

    An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions.

    НизкаяCVSS 2,3Эксплойта нетEPSS 0 %

    qnap · qts6 дек. 2024 г.

Все классы уязвимостей