Threats Tagged 'cwe-647'
View all threats tagged with 'cwe-647'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-647'
Click on any threat for detailed analysis and mitigation recommendations
0 Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. A request that should have been rejected is served instead, giving unauthenticated access to a protected upstream endpoint. This issue affects Apache APISIX: from 2.14.1 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue. Join the discussion | CVE Database V5 | 10/01/2026, 11:02:20 UTC Added: 10/01/2026, 14:56:13 UTC |
0 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. Join the discussion | CVE Database V5 | 09/23/2026, 14:05:22 UTC Added: 09/23/2026, 14:33:20 UTC |
0 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such as /user/..;foo=bar/admin is therefore not canonicalized to /admin even when path normalization is enabled. If an upstream interprets the segment according to RFC 3986 while Envoy applies routing or RBAC to the uncollapsed path, a remote client can cause path confusion and bypass path-based security policy. The relevant scope boundary is that the security consequence depends on a downstream/upstream path interpretation mismatch or a path-based Envoy decision. This issue is fixed in versions 1.36.10, 1.37.6, 1.38.4, and 1.39.1. Join the discussion | CVE Database V5 | 09/21/2026, 20:17:02 UTC Added: 09/21/2026, 20:32:08 UTC |
0 In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud. Join the discussion | CVE Database V5 | 09/03/2026, 13:41:00 UTC Added: 09/03/2026, 13:52:46 UTC |
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. Join the discussion | CVE Database V5 | 08/17/2026, 05:38:02 UTC Added: 08/07/2026, 19:42:01 UTC |
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is not affected, as it will not serve the secret.txt file because it will not pass the alias checker (only resolved resources are served). However, web applications that rely on resolved paths being provided by Jetty may be confused when receiving an unresolved path. Join the discussion | CVE Database V5 | 07/14/2026, 08:56:17 UTC Added: 07/14/2026, 09:18:34 UTC |
0 Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit, while later rewrite route matching performs an additional decodeURI() operation and can resolve the request to a protected route. This issue is fixed in version 6.4.8. Join the discussion | CVE Database V5 | 07/08/2026, 16:27:18 UTC Added: 07/08/2026, 16:59:04 UTC |
0 CVE-2026-5222 is a low-severity vulnerability in Rust Cargo version 1.68.0 where URL normalization for third-party registries using the sparse index protocol is incorrect. This flaw could allow an attacker who can publish crates in a registry hosted on a domain with multiple arbitrary-named registries to potentially obtain credentials of other users of the same registry. Exploitation requires very specific conditions, limiting the overall impact. Join the discussion | CVE Database V5 | 05/25/2026, 08:54:56 UTC Added: 05/25/2026, 09:40:18 UTC |
0 Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 was fixed in v5.15.8, the fix is insufficient as it only decodes once. By using double-encoded URLs, attackers can still bypass authentication and access any route protected by middleware pathname checks. This issue is fixed in version 5.15.8. Join the discussion | CVE Database V5 | 12/08/2025, 23:41:21 UTC Added: 12/08/2025, 23:47:05 UTC |
Showing 1 to 9 of 9 results