CWE-180— Incorrect Behavior Order: Validate Before Canonicalize
The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.— MITRE CWE catalog
38 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-180page 1 of 1
- CVE-2026-15704CRITICALCVSS 9.8EG 9.82026-07-24
In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The sh…
- CVE-2026-34475CRITICALCVSS 9.8EG 9.82026-03-27
Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.
- CVE-2026-27590CRITICALCVSS 9.8EG 9.82026-02-24
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to slice the ori…
- CVE-2026-24895CRITICALCVSS 9.8EG 9.82026-02-12
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased…
- CVE-2022-26136CRITICALCVSS 9.8EG 9.82022-07-20
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. …
- CVE-2026-73420CRITICALCVSS 9.1EG 9.12026-07-23
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normaliza…
- CVE-2022-26137HIGHCVSS 8.8EG 8.82022-07-20
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only kno…
- CVE-2026-82481HIGHCVSS 8.7EG 8.72026-08-29
The cohttp package before 6.3.0 for OCaml allows directory traversal.
- CVE-2026-52747HIGHCVSS 8.6EG 8.62026-07-10
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-fi…
- CVE-2026-48721HIGHCVSS 8.6EG 8.62026-06-24
Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is no…
- CVE-2026-49984HIGHCVSS 7.7EG 7.72026-06-26
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows-style backslashes to forward slashes. A…
- CVE-2026-62999HIGHCVSS 7.5EG 7.52026-07-31
Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an H…
- CVE-2026-45022HIGHCVSS 7.5EG 7.52026-05-27
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malfo…
- CVE-2026-39364HIGHCVSS 7.5EG 7.52026-04-07
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query param…
- CVE-2025-29787HIGHCVSS 7.3EG 7.32025-03-17
`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the `zip` crate starting with version 1.3.0 and prior to version 2.3.0, symbolic links earlie…
- CVE-2026-69246HIGHCVSS 7.2EG 7.22026-08-03
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Hos…
- CVE-2026-105050HIGHCVSS 7.1EG 7.12026-10-02
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
- CVE-2026-42462HIGHCVSS 7.0EG 7.02026-05-26
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that wou…
- CVE-2026-95811MEDIUMCVSS 6.5EG 6.52026-09-25
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost's…
- CVE-2026-69245MEDIUMCVSS 6.5EG 6.52026-08-03
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host,…
- CVE-2026-73416MEDIUMCVSS 6.1EG 6.12026-07-22
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jupyt…
- CVE-2026-93326MEDIUMCVSS 6.0EG 6.02026-10-05
A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is …
- CVE-2026-72917MEDIUMCVSS 5.9EG 5.92026-08-10
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js…
- CVE-2025-43716MEDIUMCVSS 5.8EG 5.82025-04-23
A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can bypass access controls and gain unauthorized access to vari…
- CVE-2025-33194MEDIUMCVSS 5.7EG 5.72025-11-25
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service.
- CVE-2026-100547MEDIUMCVSS 5.5EG 5.52026-09-26
OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths …
- CVE-2026-102269MEDIUMCVSS 5.4EG 5.42026-09-28
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-B…
- CVE-2026-100230MEDIUMCVSS 5.3EG 5.32026-09-25
Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written…
- CVE-2026-7120MEDIUMCVSS 5.3EG 5.32026-07-23
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can by…
- CVE-2026-39409MEDIUMCVSS 5.3EG 5.32026-04-08
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rule…
- CVE-2026-34786MEDIUMCVSS 5.3EG 5.32026-04-02
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several header_rules types against the raw URL-encoded PATH_INFO, while the underlying file-serving path is d…
- CVE-2026-76203MEDIUMCVSS 5.1EG 5.12026-08-19
Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from other users' browsers, disclosing their IP…
- CVE-2026-100674MEDIUMCVSS 4.3EG 4.32026-09-26
stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden characters by submitting Unicode letters that transform into rejected characters. Attackers can bypass …
- CVE-2026-90813MEDIUMCVSS 4.3EG 4.32026-09-14
A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incor…
- CVE-2026-97764LOWCVSS 3.7EG 3.72026-09-25
django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.
- CVE-2026-79300LOWCVSS 3.5EG 3.52026-09-12
SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization …
- CVE-2024-28607LOWCVSS 2.9EG 2.92025-03-11
The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.
- CVE-2026-82736LOWCVSS 2.1EG 2.12026-09-01
Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. Ash.Type.CiString.apply_constraints/2 (lib/ash/t…
Map vulnerabilities like CWE-180 to your infrastructure
EchelonGraph correlates every CVE — across CWE-180 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →