Threats Tagged 'cwe-551'
View all threats tagged with 'cwe-551'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-551'
Click on any threat for detailed analysis and mitigation recommendations
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster. Join the discussion | CVE Database V5 | 09/11/2026, 04:22:47 UTC Added: 09/11/2026, 04:47:43 UTC |
0 CVE-2026-16102 is a vulnerability in the Dynamic Client Registration (DCR) component of the Red Hat build of Keycloak 26.4. The default DCR policy does not properly validate claim paths for User Property mappers, enabling attackers with standard user accounts and limited Initial Access Tokens to forge administrative roles in their access tokens. This flaw allows attackers to take over clients, steal confidential secrets, and potentially gain full administrative control over the realm. Red Hat has rated this vulnerability as Important with a CVSS score of 8.1 (high severity). Join the discussion | GCVE Database | 08/05/2026, 13:50:50 UTC Added: 08/05/2026, 18:46:59 UTC |
0 CVE-2026-15573 is a vulnerability in Red Hat's build of Keycloak 26.4 where the PathMatcher component does not properly normalize URIs before comparing them to security policies. This flaw allows authenticated users to bypass fine-grained authorization controls by manipulating URLs with extra characters such as trailing slashes or matrix parameters, potentially granting access to restricted administrative areas. The vulnerability has a high severity with a CVSS score of 8.1. Red Hat has released version 26.4.14 to address this issue. Join the discussion | GCVE Database | 08/05/2026, 13:50:03 UTC Added: 08/05/2026, 18:46:59 UTC |
0 Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints. Join the discussion | CVE Database V5 | 06/26/2026, 12:20:52 UTC Added: 06/26/2026, 12:38:52 UTC |
0 A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) * github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 06/22/2026, 11:36:22 UTC Added: 05/26/2026, 20:57:58 UTC |
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39852, which addressed only literal semicolon stripping. Versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2 contain a patch. Join the discussion | GCVE Database | 06/19/2026, 20:26:39 UTC Added: 06/18/2026, 15:21:19 UTC |
0 All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints. Join the discussion | CVE Database V5 | 06/12/2026, 15:11:46 UTC Added: 06/12/2026, 15:39:34 UTC |
0 Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 15.5.16 and 16.2.5. Join the discussion | CVE Database V5 | 05/13/2026, 16:56:06 UTC Added: 05/13/2026, 17:06:28 UTC |
0 Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to be reached without the expected authorization check. This vulnerability is fixed in 15.5.16 and 16.2.5. Join the discussion | CVE Database V5 | 05/13/2026, 16:54:39 UTC Added: 05/13/2026, 17:06:28 UTC |
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intended authorization checks. This vulnerability is fixed in 15.5.16 and 16.2.5. Join the discussion | CVE Database V5 | 05/13/2026, 16:48:16 UTC Added: 05/13/2026, 17:06:28 UTC |
Showing 1 to 10 of 14 results