Skip to main content

CWE archive

CWE-177 CVEs

Programmatic archive

12 CVEs tagged with CWE-1772 Critical, 4 High, 4 Medium, 2 Low, 0 Unrated.

CVE-2026-59083

Published Jul 14, 2026

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apa…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-41041

Published Jul 13, 2026

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-6414

Published Apr 16, 2026

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. T…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-29045

Published Mar 4, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protecti…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22037

Published Jan 19, 2026

The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-22031

Published Jan 19, 2026

@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware regis…

CVSS 8.4 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-11990

Published Nov 15, 2025

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to gain CSRF token…

CVSS 3.1 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-48866

Published Dec 6, 2024

An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow r…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-23983

Published Nov 11, 2024

Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.

CVSS 5.8 · Medium

CVE-2022-3854

Published Mar 6, 2023

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27780

Published Jun 2, 2022

The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2018-3718

Published Jun 7, 2018

serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1