CWE-178— Improper Handling of Case Sensitivity
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.— MITRE CWE catalog
124 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-178page 2 of 3
- CVE-2025-59944HIGHCVSS 8.0EG 8.02025-10-03
Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sensitive files (e.g., */.cursor/mcp.json), which allows attackers to modify the content of t…
- CVE-2026-42273HIGHCVSS 7.8EG 7.82026-05-08
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are case-insensitive. This discrepancy can resu…
- CVE-2026-42272HIGHCVSS 7.8EG 7.82026-05-08
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive.…
- CVE-2001-1238HIGHCVSS 7.8EG 7.82001-07-16
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan ho…
- CVE-2026-47346HIGHCVSS 7.6EG 7.62026-06-09
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .FORM.YAML) to bypass the Form Framework's upload restriction. Maliciously crafted form definition files can be used to e…
- CVE-2026-100669HIGHCVSS 7.5EG 7.52026-09-26
Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_re…
- CVE-2026-100541HIGHCVSS 7.5EG 7.52026-09-26
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenCl…
- CVE-2026-84428HIGHCVSS 7.5EG 7.52026-09-04
fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the …
- CVE-2026-54567HIGHCVSS 7.5EG 7.52026-07-17
Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helpe…
- CVE-2026-62230HIGHCVSS 7.5EG 7.52026-07-17
Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching case-sensitive. On case…
- CVE-2026-43513HIGHCVSS 7.5EG 7.52026-05-12
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.…
- CVE-2026-33691HIGHCVSS 7.5EG 7.52026-04-02
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous…
- CVE-2026-29054HIGHCVSS 7.5EG 7.52026-03-05
Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, there is a potential vulnerability in Traefik managing the Connection header with X-Forwarded headers. When Traefik process…
- CVE-2026-27896HIGHCVSS 7.5EG 7.52026-02-26
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagg…
- CVE-2026-25992HIGHCVSS 7.5EG 7.52026-02-10
SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive string equality checks to block access to sensitive files. On case-insensitive file systems such as Windows, attackers can…
- CVE-2024-6866HIGHCVSS 7.5EG 7.52025-03-20
corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch becaus…
- CVE-2024-23331HIGHCVSS 7.5EG 7.52024-01-19
Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. T…
- CVE-2021-45893HIGHCVSS 7.5EG 7.52022-04-05
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes password guessing easier.
- CVE-2007-3365HIGHCVSS 7.5EG 7.52007-06-22
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.
- CVE-2004-1083HIGHCVSS 7.5EG 7.52004-12-03
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files be…
- CVE-2003-0411HIGHCVSS 7.5EG 7.52003-06-30
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that uses the uppercase ".JSP" extension instead of the lowercase .jsp extension.
- CVE-2002-0485HIGHCVSS 7.5EG 7.52002-08-12
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.
- CVE-2001-0795HIGHCVSS 7.5EG 7.52001-10-18
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
- CVE-2000-0497HIGHCVSS 7.5EG 7.52000-06-08
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
- CVE-2000-0498HIGHCVSS 7.5EG 7.52000-06-08
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
- CVE-2000-0499HIGHCVSS 7.5EG 7.52000-06-08
The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
- CVE-1999-0239HIGHCVSS 7.5EG 7.51998-01-01
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
- CVE-2026-3833HIGHCVSS 7.4EG 7.42026-04-30
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permit…
- CVE-2025-46701HIGHCVSS 7.3EG 7.32025-05-29
Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apach…
- CVE-2026-89322HIGHCVSS 7.2EG 7.22026-10-07
Vault and Vault Enterprise did not consistently evaluate ACL policies against the canonical form of resource and policy names. This may allow an authenticated user with delegated permissions to bypass an explicit deny restriction and acces…
- CVE-2026-102131HIGHCVSS 7.2EG 7.22026-09-30
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have …
- CVE-2026-54528HIGHCVSS 7.1EG 7.12026-06-19
JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensit…
- CVE-2026-105570MEDIUMCVSS 6.7EG 6.72026-10-08
Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use…
- CVE-2026-77281MEDIUMCVSS 6.5EG 6.52026-09-17
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() c…
- CVE-2026-89012MEDIUMCVSS 6.5EG 6.52026-09-11
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylis…
- CVE-2026-78959MEDIUMCVSS 6.5EG 6.52026-08-25
Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: …
- CVE-2025-50864MEDIUMCVSS 6.5EG 6.52025-08-20
An Origin Validation Error in the elysia-cors library thru 1.3.0 allows attackers to bypass Cross-Origin Resource Sharing (CORS) restrictions. The library incorrectly validates the supplied origin by checking if it is a substring of any do…
- CVE-2023-46218MEDIUMCVSS 6.5EG 6.52023-12-07
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrel…
- CVE-2021-28323MEDIUMCVSS 6.5EG 6.52021-04-13
Windows DNS Information Disclosure Vulnerability
- CVE-2021-25920MEDIUMCVSS 6.5EG 6.52021-03-22
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.
- CVE-2026-92700MEDIUMCVSS 6.3EG 6.32026-09-23
Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case variants can bypass hide rules …
- CVE-2026-84303MEDIUMCVSS 6.3EG 6.32026-09-01
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are l…
- CVE-2026-82726MEDIUMCVSS 6.3EG 6.32026-08-31
Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdomain/2 stripped t…
- CVE-2026-66883MEDIUMCVSS 6.3EG 6.32026-08-04
Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen sessio…
- CVE-2026-73416MEDIUMCVSS 6.1EG 6.12026-07-22
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jupyt…
- CVE-2020-15234MEDIUMCVSS 6.1EG 6.12020-10-02
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL provided at the OAuth2 Authorization Endpoint where compared usi…
- CVE-2026-48595MEDIUMCVSS 5.9EG 5.92026-06-02
Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin redi…
- CVE-2026-49336MEDIUMCVSS 5.5EG 5.52026-06-19
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `…
- CVE-2017-8493MEDIUMCVSS 5.5EG 5.52017-06-15
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to set variables that are either read-only or require authentication when Windows fails to e…
- CVE-2026-73476MEDIUMCVSS 5.4EG 5.42026-09-02
Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.
Map vulnerabilities like CWE-178 to your infrastructure
EchelonGraph correlates every CVE — across CWE-178 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →