Skip to main content

CWE archive

CWE-178 CVEs

Programmatic archive

85 CVEs tagged with CWE-17816 Critical, 41 High, 17 Medium, 11 Low, 0 Unrated.

CVE-2026-15617

Published Jul 23, 2026

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different ident…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-53595

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenC…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-62230

Published Jul 17, 2026

Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-55170

Published Jul 9, 2026

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive u…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-54528

Published Jul 8, 2026

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce exclu…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-54763

Published Jul 6, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoo…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-14617

Published Jul 3, 2026

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/…

CVSS 1.3 · Low
evidence mentions
8
Buzz score
30.0

CVE-2026-58057

Published Jun 28, 2026

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensi…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
38.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-57234

Published Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::S…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45135

Published Jun 23, 2026

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go m…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48794

Published Jun 19, 2026

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36…

CVSS 1.3 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-47203

Published Jun 19, 2026

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38…

CVSS 2.9 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-49336

Published Jun 19, 2026

@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fe…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-53721

Published Jun 12, 2026

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sens…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-45062

Published Jun 10, 2026

FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.Ign…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-47346

Published Jun 9, 2026

Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction…

CVSS 7.6 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-46392

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8404

Published Jun 3, 2026

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directi…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-48595

Published Jun 2, 2026

Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedi…

CVSS 8.2 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-44367

Published Jun 2, 2026

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to i…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-47323

Published May 19, 2026

Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cx…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-43513

Published May 12, 2026

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42273

Published May 8, 2026

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HT…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-42272

Published May 8, 2026

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manne…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1
Showing 1-25 of 85 CVEsPage 1 of 4