Threats Tagged 'cwe-36'
View all threats tagged with 'cwe-36'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-36'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54202: CWE-36 Absolute path traversal in Tobit Laboratories AG TeamDavidCVE-2026-54202 0 Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary locations, including sensitive directories such as C:\Windows or for different users. This issue affects TeamDavid through Rollout 524. Join the discussion | CVE Database V5 | 08/07/2026, 09:43:41 UTC Added: 08/07/2026, 10:12:15 UTC |
CVE-2026-61891: CWE-22 in Eclipse Foundation Eclipse TheiaCVE-2026-61891 0 Eclipse Theia versions up to and including 1.73.1 have a vulnerability in the @theia/filesystem backend where HTTP file-download endpoints allow unauthenticated clients to read arbitrary files on the backend filesystem. This occurs because client-supplied URIs are converted directly to filesystem paths without confinement, and HTTP middleware does not enforce token validation for non-WebSocket HTTP requests in browser deployments. Electron mode is not affected by this issue. Join the discussion | GCVE Database | 08/05/2026, 11:03:01 UTC Added: 08/05/2026, 15:31:19 UTC |
CVE-2026-61891: CWE-22 in Eclipse Foundation Eclipse TheiaCVE-2026-61891 0 In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to the workspace or any allow-listed root. In browser (non-Electron) deployments the connection token is enforced only on WebSocket upgrades; the HTTP middleware in `@theia/core` re-issues the cookie and calls `next()` without rejecting tokenless HTTP requests, so these endpoints are reachable without a valid token. As a result an unauthenticated client can read any file readable by the backend process, including files outside the opened workspace (for example `/etc/hosts`, SSH keys, or tokens). Electron mode uses a separate `ElectronSecurityToken` and is not affected via this path. Join the discussion | CVE Database V5 | 08/05/2026, 11:03:01 UTC Added: 08/05/2026, 11:57:50 UTC |
CVE-2026-13346: CWE-36 Absolute path traversal in Python Packaging Authority pipCVE-2026-13346 0 pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time. Join the discussion | CVE Database V5 | 07/29/2026, 18:33:50 UTC Added: 07/29/2026, 18:52:44 UTC |
CVE-2026-13189: CWE-36 Absolute Path Traversal in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13189 0 In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests. Join the discussion | CVE Database V5 | 07/22/2026, 13:42:19 UTC Added: 07/22/2026, 14:08:05 UTC |
CVE-2026-57211: CWE-36: Absolute Path Traversal in rabbitmq rabbitmq-serverCVE-2026-57211 0 RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6. Join the discussion | CVE Database V5 | 07/10/2026, 20:16:01 UTC Added: 07/10/2026, 20:48:11 UTC |
Showing 1 to 6 of 6 results