CWE-647 · 16 записей
Use of Non-Canonical URL Paths for Authorization Decisions
CVE этого класса
16 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2022-43939Готовый эксплойт | Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisionshitachi · vantara pentaho business analytics server · CWE-647 | Критическая9,8 | KEV | 92,3 % | 3 апр. 2023 г. |
37Наблюдать | GHSA-f54f-hr32-586fЭксплойта нет | Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URLPyPI · browser-use · CWE-647 | Критическая9,3 | — | — | 3 мая 2025 г. |
35Наблюдать | CVE-2026-80515Эксплойта нет | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides wheteclipse foundation · eclipse arrowhead · CWE-647 | Высокая8,9 | — | 0,5 % | 3 сент. 2026 г. |
32Наблюдать | CVE-2026-62685Эксплойта нет | File Browser: Colliding username normalization gives two users the same home directoryfilebrowser · filebrowser · CWE-647 | Высокая8,1 | — | 0,6 % | 15 июл. 2026 г. |
32Наблюдать | CVE-2026-59731Эксплойта нет | Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatchwithastro · astro · CWE-647 | Высокая8,2 | — | 0,5 % | 8 июл. 2026 г. |
29Наблюдать | CVE-2025-64500Proof of concept | Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypasssensiolabs · httpfoundation · CWE-647 | Высокая7,3 | — | 1,3 % | 12 нояб. 2025 г. |
26Наблюдать | CVE-2025-66202Эксплойта нет | Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765astro · astro · CWE-647 | Средняя6,5 | — | 0,3 % | 8 дек. 2025 г. |
26Наблюдать | CVE-2025-9909Эксплойта нет | Aap-gateway: improper path validation in gateway allows credential exfiltrationredhat · ansible automation platform · CWE-647 | Средняя6,7 | — | 0,2 % | 27 февр. 2026 г. |
26Наблюдать | GHSA-c534-2w9c-x7fmЭксплойта нет | Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resourcesGo · github.com/zxh326/kite · CWE-647 | Средняя6,5 | — | — | 24 июл. 2026 г. |
21Наблюдать | CVE-2026-73551Эксплойта нет | Envoy: Path normalization does not handle dot and dotdot segments with parametersenvoyproxy · envoy · CWE-647 | Средняя5,3 | — | 0,6 % | 21 сент. 2026 г. |
21Наблюдать | CVE-2026-8384Эксплойта нет | In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admieclipse · jetty · CWE-647 | Средняя5,3 | — | 0,3 % | 14 июл. 2026 г. |
16Наблюдать | CVE-2025-47241Эксплойта нет | In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authoritybrowser-use · browser-use · CWE-647 | Средняя4,0 | — | 0,5 % | 3 мая 2025 г. |
16Наблюдать | CVE-2026-15970Эксплойта нет | L7 intention authorization bypass via custom public listenerhashicorp · consul · CWE-647 | Средняя4,2 | — | 0,2 % | 7 авг. 2026 г. |
14Наблюдать | CVE-2026-71178Эксплойта нет | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorizationdell · policy manager for secure connect gateway · CWE-647 | Низкая3,7 | — | 0,2 % | 23 сент. 2026 г. |
13Наблюдать | CVE-2025-43916Эксплойта нет | Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authorisonos · api.sonos.com · CWE-647 | Низкая3,4 | — | 0,2 % | 21 апр. 2025 г. |
9Наблюдать | CVE-2026-5222Эксплойта нет | Cargo can be coerced to share credentials between registriesrust-lang · cargo · CWE-647 | Низкая2,3 | — | 0,5 % | 25 мая 2026 г. |
- CVE-2022-4393997Срочно
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- GHSA-f54f-hr32-586f37Наблюдать
Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL
КритическаяCVSS 9,3Эксплойта нетPyPI · browser-use3 мая 2025 г.
- CVE-2026-8051535Наблюдать
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whet
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %eclipse foundation · eclipse arrowhead3 сент. 2026 г.
- CVE-2026-6268532Наблюдать
File Browser: Colliding username normalization gives two users the same home directory
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %filebrowser · filebrowser15 июл. 2026 г.
- CVE-2026-5973132Наблюдать
Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %withastro · astro8 июл. 2026 г.
- CVE-2025-6450029Наблюдать
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
ВысокаяCVSS 7,3Proof of conceptEPSS 1 %sensiolabs · httpfoundation12 нояб. 2025 г.
- CVE-2025-6620226Наблюдать
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
СредняяCVSS 6,5Эксплойта нетEPSS 0 %astro · astro8 дек. 2025 г.
- CVE-2025-990926Наблюдать
Aap-gateway: improper path validation in gateway allows credential exfiltration
СредняяCVSS 6,7Эксплойта нетEPSS 0 %redhat · ansible automation platform27 февр. 2026 г.
- GHSA-c534-2w9c-x7fm26Наблюдать
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
СредняяCVSS 6,5Эксплойта нетGo · github.com/zxh326/kite24 июл. 2026 г.
- CVE-2026-7355121Наблюдать
Envoy: Path normalization does not handle dot and dotdot segments with parameters
СредняяCVSS 5,3Эксплойта нетEPSS 1 %envoyproxy · envoy21 сент. 2026 г.
- CVE-2026-838421Наблюдать
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admi
СредняяCVSS 5,3Эксплойта нетEPSS 0 %eclipse · jetty14 июл. 2026 г.
- CVE-2025-4724116Наблюдать
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority
СредняяCVSS 4,0Эксплойта нетEPSS 0 %browser-use · browser-use3 мая 2025 г.
- CVE-2026-1597016Наблюдать
L7 intention authorization bypass via custom public listener
СредняяCVSS 4,2Эксплойта нетEPSS 0 %hashicorp · consul7 авг. 2026 г.
- CVE-2026-7117814Наблюдать
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization
НизкаяCVSS 3,7Эксплойта нетEPSS 0 %dell · policy manager for secure connect gateway23 сент. 2026 г.
- CVE-2025-4391613Наблюдать
Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authori
НизкаяCVSS 3,4Эксплойта нетEPSS 0 %sonos · api.sonos.com21 апр. 2025 г.
- CVE-2026-52229Наблюдать
Cargo can be coerced to share credentials between registries
НизкаяCVSS 2,3Эксплойта нетEPSS 0 %rust-lang · cargo25 мая 2026 г.