CWE-647 · 16 kayıt
Use of Non-Canonical URL Paths for Authorization Decisions
Bu sınıftaki CVE’ler
16 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
97Hemen | CVE-2022-43939Silahlaştırılmış | Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisionshitachi · vantara pentaho business analytics server · CWE-647 | Kritik9,8 | KEV | %92,3 | 3 Nis 2023 |
37İzleyin | GHSA-f54f-hr32-586fİstismar yok | Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URLPyPI · browser-use · CWE-647 | Kritik9,3 | — | — | 3 May 2025 |
35İzleyin | CVE-2026-80515İstismar yok | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides wheteclipse foundation · eclipse arrowhead · CWE-647 | Yüksek8,9 | — | %0,5 | 3 Eyl 2026 |
32İzleyin | CVE-2026-62685İstismar yok | File Browser: Colliding username normalization gives two users the same home directoryfilebrowser · filebrowser · CWE-647 | Yüksek8,1 | — | %0,6 | 15 Tem 2026 |
32İzleyin | CVE-2026-59731İstismar yok | Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatchwithastro · astro · CWE-647 | Yüksek8,2 | — | %0,5 | 8 Tem 2026 |
29İzleyin | CVE-2025-64500Kavram kanıtı | Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypasssensiolabs · httpfoundation · CWE-647 | Yüksek7,3 | — | %1,3 | 12 Kas 2025 |
26İzleyin | CVE-2025-66202İstismar yok | Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765astro · astro · CWE-647 | Orta6,5 | — | %0,3 | 8 Ara 2025 |
26İzleyin | CVE-2025-9909İstismar yok | Aap-gateway: improper path validation in gateway allows credential exfiltrationredhat · ansible automation platform · CWE-647 | Orta6,7 | — | %0,2 | 27 Şub 2026 |
26İzleyin | GHSA-c534-2w9c-x7fmİstismar yok | Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resourcesGo · github.com/zxh326/kite · CWE-647 | Orta6,5 | — | — | 24 Tem 2026 |
21İzleyin | CVE-2026-73551İstismar yok | Envoy: Path normalization does not handle dot and dotdot segments with parametersenvoyproxy · envoy · CWE-647 | Orta5,3 | — | %0,6 | 21 Eyl 2026 |
21İzleyin | CVE-2026-8384İstismar yok | In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admieclipse · jetty · CWE-647 | Orta5,3 | — | %0,3 | 14 Tem 2026 |
16İzleyin | CVE-2025-47241İstismar yok | In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authoritybrowser-use · browser-use · CWE-647 | Orta4,0 | — | %0,5 | 3 May 2025 |
16İzleyin | CVE-2026-15970İstismar yok | L7 intention authorization bypass via custom public listenerhashicorp · consul · CWE-647 | Orta4,2 | — | %0,2 | 7 Ağu 2026 |
14İzleyin | CVE-2026-71178İstismar yok | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorizationdell · policy manager for secure connect gateway · CWE-647 | Düşük3,7 | — | %0,2 | 6 gün önce |
13İzleyin | CVE-2025-43916İstismar yok | Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authorisonos · api.sonos.com · CWE-647 | Düşük3,4 | — | %0,2 | 21 Nis 2025 |
9İzleyin | CVE-2026-5222İstismar yok | Cargo can be coerced to share credentials between registriesrust-lang · cargo · CWE-647 | Düşük2,3 | — | %0,5 | 25 May 2026 |
- CVE-2022-4393997Hemen
Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92hitachi · vantara pentaho business analytics server3 Nis 2023
- GHSA-f54f-hr32-586f37İzleyin
Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL
KritikCVSS 9,3İstismar yokPyPI · browser-use3 May 2025
- CVE-2026-8051535İzleyin
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whet
YüksekCVSS 8,9İstismar yokEPSS %0eclipse foundation · eclipse arrowhead3 Eyl 2026
- CVE-2026-6268532İzleyin
File Browser: Colliding username normalization gives two users the same home directory
YüksekCVSS 8,1İstismar yokEPSS %1filebrowser · filebrowser15 Tem 2026
- CVE-2026-5973132İzleyin
Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
YüksekCVSS 8,2İstismar yokEPSS %0withastro · astro8 Tem 2026
- CVE-2025-6450029İzleyin
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
YüksekCVSS 7,3Kavram kanıtıEPSS %1sensiolabs · httpfoundation12 Kas 2025
- CVE-2025-6620226İzleyin
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
OrtaCVSS 6,5İstismar yokEPSS %0astro · astro8 Ara 2025
- CVE-2025-990926İzleyin
Aap-gateway: improper path validation in gateway allows credential exfiltration
OrtaCVSS 6,7İstismar yokEPSS %0redhat · ansible automation platform27 Şub 2026
- GHSA-c534-2w9c-x7fm26İzleyin
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
OrtaCVSS 6,5İstismar yokGo · github.com/zxh326/kite24 Tem 2026
- CVE-2026-7355121İzleyin
Envoy: Path normalization does not handle dot and dotdot segments with parameters
OrtaCVSS 5,3İstismar yokEPSS %1envoyproxy · envoy21 Eyl 2026
- CVE-2026-838421İzleyin
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admi
OrtaCVSS 5,3İstismar yokEPSS %0eclipse · jetty14 Tem 2026
- CVE-2025-4724116İzleyin
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority
OrtaCVSS 4,0İstismar yokEPSS %0browser-use · browser-use3 May 2025
- CVE-2026-1597016İzleyin
L7 intention authorization bypass via custom public listener
OrtaCVSS 4,2İstismar yokEPSS %0hashicorp · consul7 Ağu 2026
- CVE-2026-7117814İzleyin
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization
DüşükCVSS 3,7İstismar yokEPSS %0dell · policy manager for secure connect gateway6 gün önce
- CVE-2025-4391613İzleyin
Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authori
DüşükCVSS 3,4İstismar yokEPSS %0sonos · api.sonos.com21 Nis 2025
- CVE-2026-52229İzleyin
Cargo can be coerced to share credentials between registries
DüşükCVSS 2,3İstismar yokEPSS %0rust-lang · cargo25 May 2026