CWE-178

CWE-178 · 8 records · 7 with a public proof-of-concept

Records the NVD classes under CWE-178, highest CVSS first.

  1. HIGH 8.8CVE-2026-100580public PoC

    OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-case payload kind can pass the agent-facing shell-execution guard and later normalize into a command job. An actor able to steer a tool…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.4CVE-2026-100693public PoC

    Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch fro…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-77560public PoC

    Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app a…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.1CVE-2026-15573

    A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parame…

    build of keycloak · data grid · jboss enterprise application platform expansion pack · single sign-on

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.5CVE-2026-100669public PoC

    Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, s…

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-100541public PoC

    OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-92700public PoC

    Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/fileserver/staticfiles.go, fileHidden() uses case-sensitive filepath.Match checks, so case variants can bypass hide rules on case-insensitive f…

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-66883public PoC

    Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth control against replay of a stolen session. This vulnerabilit…

    AI risk analysis on Exploit-DB.ai →