Threats Tagged 'cwe-178'
View all threats tagged with 'cwe-178'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-178'
Click on any threat for detailed analysis and mitigation recommendations
0 Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased hostname. The lookup in internal/service/access_controls_service.go through lookupStaticACLs and GetAccessControls, and the Docker-label fallback in internal/service/docker_service.go through GetLabels, can miss the configured app and return an empty access-control object. internal/controller/proxy_controller.go proxyHandler then treats the empty user, group, OAuth, LDAP, and IP restrictions as permissive and returns an authenticated result for an app that should exclude the user. Unauthenticated users remain subject to login, and global login-time allowlists are not bypassed. This issue is fixed in version 5.1.2. Join the discussion | CVE Database V5 | 09/21/2026, 16:39:18 UTC Added: 09/21/2026, 22:12:11 UTC |
0 Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQueryString for a second placeholder expansion when a rewrite URI ends with a literal question mark, allowing injected environment or request-variable placeholders to disclose data and, when the file provider is registered, allowing injected file placeholders to disclose readable files. The issue is fixed in version 2.11.4. Join the discussion | CVE Database V5 | 09/17/2026, 21:04:58 UTC Added: 09/17/2026, 21:17:11 UTC |
0 MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without canonicalizing filesystem-equivalent segment names. On case-insensitive macOS and Windows filesystems, case variants of .git, .obsidian, or node_modules pass both isAllowed() and isAllowedForListing() even though the operating system opens the restricted directory, and Windows trailing dots or spaces provide the same bypass. An attacker who influences a path selected by an AI agent can use the bypass in read, write, move, search, or listing operations to expose or modify sensitive repository and Obsidian metadata. Vault-root .. containment is not affected. This issue is fixed in version 0.11.4. Join the discussion | CVE Database V5 | 09/15/2026, 17:49:10 UTC Added: 09/15/2026, 18:02:11 UTC |
0 Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept denylist. An attacker who controls the name override can use a mixed-case dangerous extension to bypass a lowercase denylist and store the file in the served upload directory. Exploitation requires a denylist configuration, a user-influenced name override, and a deployment that resolves or executes extensions case-insensitively; pure allowlists remain protected and path containment is not bypassed. On an execution-capable upload directory, the stored file can execute with the web server's privileges and affect confidentiality, integrity, and availability. This issue is fixed in version 1.6.0. Join the discussion | CVE Database V5 | 09/14/2026, 17:15:49 UTC Added: 09/14/2026, 17:33:54 UTC |
CVE-2026-84303 is a medium severity vulnerability in grpc-go prior to version 1.83.1. It involves improper handling of case sensitivity in the xDS RBAC HTTP filter, causing header matcher names not to be lowercased as expected. This leads to DENY policies with mixed-case header names failing to match and thus failing open, allowing unauthorized requests. Additionally, certain headers like :Scheme, Grpc-Status, and Host are improperly handled, affecting validation and rewriting. The issue is fixed in grpc-go version 1.83.1. Join the discussion | CVE Database V5 | 09/10/2026, 00:00:00 UTC Added: 09/01/2026, 18:22:44 UTC |
0 Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network access to a deployment where this condition occurs can perform arbitrary administrative operations, resulting in full impact of data confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 09/08/2026, 16:12:26 UTC Added: 09/08/2026, 16:39:04 UTC |
0 Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13. Join the discussion | CVE Database V5 | 09/02/2026, 12:32:38 UTC Added: 09/02/2026, 12:52:54 UTC |
CVE-2026-73270 is a high-severity vulnerability in Erlang/OTP's inets httpd module that improperly handles case sensitivity on case-insensitive filesystems. It allows remote unauthenticated attackers to bypass mod_auth directory protections by requesting files with different casing, leading to unauthorized file disclosure. This affects multiple OTP and inets versions prior to specific fixed releases. Case-sensitive filesystems are not affected. Join the discussion | CVE Database V5 | 09/01/2026, 14:48:53 UTC Added: 09/01/2026, 14:53:31 UTC |
CVE-2026-82726 is a medium severity vulnerability in ash-project's ash_phoenix component. It involves a permissive regular expression used to parse the Host header, allowing a remote client to manipulate tenant selection or degrade requests by sending crafted Host headers. The root host pattern was interpolated unsafely, causing unintended matches and case sensitivity issues. This affects versions from 2.1.26 up to but not including 2.3.25. Join the discussion | CVE Database V5 | 08/31/2026, 03:05:38 UTC Added: 08/31/2026, 03:38:19 UTC |
CVE-2026-59335 is a high-severity vulnerability in Cloud Foundry UAA affecting deployments backed by MySQL with default collation. It involves improper handling of case sensitivity in the identity zone authorization check, allowing a remote authenticated attacker with zones.write authority to bypass restrictions by using non-lowercase zone identifiers. This leads to unauthorized access to the privileged system identity zone, enabling the attacker to overwrite the system zone's JWT signing key and forge tokens with admin privileges, fully compromising UAA and dependent Cloud Foundry deployments. PostgreSQL and HSQLDB backends are not affected. Join the discussion | CVE Database V5 | 08/25/2026, 11:05:11 UTC Added: 08/25/2026, 11:22:53 UTC |
Showing 1 to 10 of 39 results