CWE-436
CWE-436 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-436, highest CVSS first.
- HIGH 7.7CVE-2026-106505public PoC
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a re…
- HIGH 7.5CVE-2026-73553public PoC
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix before matching but the RBA…
- MEDIUM 5.3CVE-2026-73511public PoC
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolon matrix parameters fro…