CWE-180 · 32 kayıt
Incorrect Behavior Order: Validate Before Canonicalize
Bu sınıftaki CVE’ler
32 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2022-26136İstismar yok | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third patlassian · bamboo · CWE-180 | Kritik9,8 | — | %5,4 | 20 Tem 2022 |
40Planlayın | CVE-2024-24790İstismar yok | Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netipgolang · go · CWE-180 | Kritik9,8 | — | %2,0 | 5 Haz 2024 |
39İzleyin | CVE-2026-15704İstismar yok | CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Componentseclipse foundation · eclipse basyx go components · CWE-180 | Kritik9,8 | — | %0,7 | 24 Tem 2026 |
39İzleyin | CVE-2026-34475İstismar yok | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / varnish-software · varnish enterprise · CWE-180 | Kritik9,8 | — | %0,4 | 27 Mar 2026 |
36İzleyin | CVE-2022-26137İstismar yok | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked watlassian · bamboo · CWE-180 | Yüksek8,8 | — | %2,3 | 20 Tem 2022 |
36İzleyin | CVE-2026-73420İstismar yok | NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypassnextauthjs · next-auth · CWE-180 | Kritik9,1 | — | %0,7 | 13 Ağu 2026 |
35İzleyin | CVE-2026-24895İstismar yok | FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary filesphp · frankenphp · CWE-180 | Yüksek8,9 | — | %0,6 | 12 Şub 2026 |
34İzleyin | CVE-2026-82481İstismar yok | The cohttp package before 6.3.0 for OCaml allows directory traversal.mirage · cohttp · CWE-180 | Yüksek8,7 | — | %0,7 | 29 Ağu 2026 |
34İzleyin | CVE-2026-52747İstismar yok | ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypassowasp · modsecurity · CWE-180 | Yüksek8,6 | — | %0,5 | 10 Tem 2026 |
34İzleyin | CVE-2026-48721İstismar yok | Warp: Env-var prefixes can lead to denylisted command autoexecutionwarpdotdev · warp · CWE-180 | Yüksek8,6 | — | %0,2 | 24 Haz 2026 |
32İzleyin | CVE-2026-39364Kavram kanıtı | Vite has a `server.fs.deny` bypass with queriesvitejs · vite · CWE-180 | Yüksek8,2 | — | %1,5 | 7 Nis 2026 |
28İzleyin | CVE-2026-69246İstismar yok | Guzzle: Noncanonical host can bypass host-based checksguzzle · guzzle · CWE-180 | Yüksek7,2 | — | %0,4 | 3 Ağu 2026 |
28İzleyin | CVE-2026-42462İstismar yok | Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuringfedify-dev · fedify · CWE-180 | Yüksek7,0 | — | %0,2 | 10 Haz 2026 |
28İzleyin | CVE-2026-45022İstismar yok | go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Gitgo-git project · go-git · CWE-180 | Yüksek7,0 | — | %0,2 | 27 May 2026 |
28İzleyin | CVE-2025-33194İstismar yok | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data.nvidia · dgx os · CWE-180 | Yüksek7,1 | — | %0,2 | 25 Kas 2025 |
27İzleyin | CVE-2026-100547İstismar yok | OpenClaw before 2026.8.1 Authentication Bypass via File URLopenclaw · openclaw · CWE-180 | Orta6,8 | — | %0,1 | 4 gün önce |
26İzleyin | CVE-2026-95811İstismar yok | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path CWE-180 | Orta6,5 | — | %0,4 | 5 gün önce |
26İzleyin | CVE-2026-69245İstismar yok | Guzzle: Noncanonical cookie domain keeps subdomain scopeguzzle · guzzle · CWE-180 | Orta6,5 | — | %0,2 | 3 Ağu 2026 |
25İzleyin | CVE-2026-39409İstismar yok | Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresseshono · hono · CWE-180 | Orta6,3 | — | %0,4 | 8 Nis 2026 |
23İzleyin | CVE-2025-43716İstismar yok | A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9.ivanti · landesk management suite · CWE-180 | Orta5,8 | — | %1,2 | 23 Nis 2025 |
23İzleyin | CVE-2026-72917İstismar yok | AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalizationmintplex-labs · anything-llm · CWE-180 | Orta5,9 | — | %0,3 | 10 Ağu 2026 |
22İzleyin | GHSA-7jmw-8259-q9jxİstismar yok | Traefik has unexpected behavior with IPv4-mapped IPv6 addressesGo · github.com/traefik/traefik/v3 · CWE-180 | Orta5,5 | — | — | 11 Haz 2024 |
21İzleyin | CVE-2026-100230İstismar yok | Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versinput-leap · input leap · CWE-180 | Orta5,3 | — | %0,7 | 5 gün önce |
21İzleyin | CVE-2026-7120İstismar yok | @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Pathsfastify · fastify-static · CWE-180 | Orta5,3 | — | %0,4 | 23 Tem 2026 |
21İzleyin | CVE-2026-34786İstismar yok | Rack: Rack::Static header_rules bypass via URL-encoded pathsrack · rack · CWE-180 | Orta5,3 | — | %0,3 | 2 Nis 2026 |
- CVE-2022-2613641Planlayın
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third p
KritikCVSS 9,8İstismar yokEPSS %5atlassian · bamboo20 Tem 2022
- CVE-2024-2479040Planlayın
Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
KritikCVSS 9,8İstismar yokEPSS %2golang · go5 Haz 2024
- CVE-2026-1570439İzleyin
CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
KritikCVSS 9,8İstismar yokEPSS %1eclipse foundation · eclipse basyx go components24 Tem 2026
- CVE-2026-3447539İzleyin
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of /
KritikCVSS 9,8İstismar yokEPSS %0varnish-software · varnish enterprise27 Mar 2026
- CVE-2022-2613736İzleyin
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked w
YüksekCVSS 8,8İstismar yokEPSS %2atlassian · bamboo20 Tem 2022
- CVE-2026-7342036İzleyin
NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
KritikCVSS 9,1İstismar yokEPSS %1nextauthjs · next-auth13 Ağu 2026
- CVE-2026-2489535İzleyin
FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary files
YüksekCVSS 8,9İstismar yokEPSS %1php · frankenphp12 Şub 2026
- CVE-2026-8248134İzleyin
The cohttp package before 6.3.0 for OCaml allows directory traversal.
YüksekCVSS 8,7İstismar yokEPSS %1mirage · cohttp29 Ağu 2026
- CVE-2026-5274734İzleyin
ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
YüksekCVSS 8,6İstismar yokEPSS %0owasp · modsecurity10 Tem 2026
- CVE-2026-4872134İzleyin
Warp: Env-var prefixes can lead to denylisted command autoexecution
YüksekCVSS 8,6İstismar yokEPSS %0warpdotdev · warp24 Haz 2026
- CVE-2026-3936432İzleyin
Vite has a `server.fs.deny` bypass with queries
YüksekCVSS 8,2Kavram kanıtıEPSS %2vitejs · vite7 Nis 2026
- CVE-2026-6924628İzleyin
Guzzle: Noncanonical host can bypass host-based checks
YüksekCVSS 7,2İstismar yokEPSS %0guzzle · guzzle3 Ağu 2026
- CVE-2026-4246228İzleyin
Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
YüksekCVSS 7,0İstismar yokEPSS %0fedify-dev · fedify10 Haz 2026
- CVE-2026-4502228İzleyin
go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
YüksekCVSS 7,0İstismar yokEPSS %0go-git project · go-git27 May 2026
- CVE-2025-3319428İzleyin
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data.
YüksekCVSS 7,1İstismar yokEPSS %0nvidia · dgx os25 Kas 2025
- CVE-2026-10054727İzleyin
OpenClaw before 2026.8.1 Authentication Bypass via File URL
OrtaCVSS 6,8İstismar yokEPSS %0openclaw · openclaw4 gün önce
- CVE-2026-9581126İzleyin
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path
OrtaCVSS 6,5İstismar yokEPSS %05 gün önce
- CVE-2026-6924526İzleyin
Guzzle: Noncanonical cookie domain keeps subdomain scope
OrtaCVSS 6,5İstismar yokEPSS %0guzzle · guzzle3 Ağu 2026
- CVE-2026-3940925İzleyin
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
OrtaCVSS 6,3İstismar yokEPSS %0hono · hono8 Nis 2026
- CVE-2025-4371623İzleyin
A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9.
OrtaCVSS 5,8İstismar yokEPSS %1ivanti · landesk management suite23 Nis 2025
- CVE-2026-7291723İzleyin
AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization
OrtaCVSS 5,9İstismar yokEPSS %0mintplex-labs · anything-llm10 Ağu 2026
- GHSA-7jmw-8259-q9jx22İzleyin
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses
OrtaCVSS 5,5İstismar yokGo · github.com/traefik/traefik/v311 Haz 2024
- CVE-2026-10023021İzleyin
Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / vers
OrtaCVSS 5,3İstismar yokEPSS %1input-leap · input leap5 gün önce
- CVE-2026-712021İzleyin
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
OrtaCVSS 5,3İstismar yokEPSS %0fastify · fastify-static23 Tem 2026
- CVE-2026-3478621İzleyin
Rack: Rack::Static header_rules bypass via URL-encoded paths
OrtaCVSS 5,3İstismar yokEPSS %0rack · rack2 Nis 2026