İçeriğe atla
Noroxi

CWE-647 · 16 kayıt

Use of Non-Canonical URL Paths for Authorization Decisions

Bu sınıftaki CVE’ler

16 kayıt

  • Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    hitachi · vantara pentaho business analytics server3 Nis 2023

  • Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL

    KritikCVSS 9,3İstismar yok

    PyPI · browser-use3 May 2025

  • CVE-2026-80515
    35İzleyin

    In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whet

    YüksekCVSS 8,9İstismar yokEPSS %0

    eclipse foundation · eclipse arrowhead3 Eyl 2026

  • CVE-2026-62685
    32İzleyin

    File Browser: Colliding username normalization gives two users the same home directory

    YüksekCVSS 8,1İstismar yokEPSS %1

    filebrowser · filebrowser15 Tem 2026

  • CVE-2026-59731
    32İzleyin

    Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

    YüksekCVSS 8,2İstismar yokEPSS %0

    withastro · astro8 Tem 2026

  • CVE-2025-64500
    29İzleyin

    Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

    YüksekCVSS 7,3Kavram kanıtıEPSS %1

    sensiolabs · httpfoundation12 Kas 2025

  • CVE-2025-66202
    26İzleyin

    Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    OrtaCVSS 6,5İstismar yokEPSS %0

    astro · astro8 Ara 2025

  • CVE-2025-9909
    26İzleyin

    Aap-gateway: improper path validation in gateway allows credential exfiltration

    OrtaCVSS 6,7İstismar yokEPSS %0

    redhat · ansible automation platform27 Şub 2026

  • Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

    OrtaCVSS 6,5İstismar yok

    Go · github.com/zxh326/kite24 Tem 2026

  • CVE-2026-73551
    21İzleyin

    Envoy: Path normalization does not handle dot and dotdot segments with parameters

    OrtaCVSS 5,3İstismar yokEPSS %1

    envoyproxy · envoy21 Eyl 2026

  • CVE-2026-8384
    21İzleyin

    In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admi

    OrtaCVSS 5,3İstismar yokEPSS %0

    eclipse · jetty14 Tem 2026

  • CVE-2025-47241
    16İzleyin

    In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority

    OrtaCVSS 4,0İstismar yokEPSS %0

    browser-use · browser-use3 May 2025

  • CVE-2026-15970
    16İzleyin

    L7 intention authorization bypass via custom public listener

    OrtaCVSS 4,2İstismar yokEPSS %0

    hashicorp · consul7 Ağu 2026

  • CVE-2026-71178
    14İzleyin

    Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization

    DüşükCVSS 3,7İstismar yokEPSS %0

    dell · policy manager for secure connect gateway6 gün önce

  • CVE-2025-43916
    13İzleyin

    Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authori

    DüşükCVSS 3,4İstismar yokEPSS %0

    sonos · api.sonos.com21 Nis 2025

  • CVE-2026-5222
    9İzleyin

    Cargo can be coerced to share credentials between registries

    DüşükCVSS 2,3İstismar yokEPSS %0

    rust-lang · cargo25 May 2026

Tüm zafiyet sınıfları