CWE-647
CWE-647 · 3 records · 1 with a public proof-of-concept
Records the NVD classes under CWE-647, highest CVSS first.
- MEDIUM 5.3CVE-2026-73551public PoC
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such …
- LOW 3.7CVE-2026-71178
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l…
policy manager for secure connect gateway
- UNSCOREDCVE-2026-94269
Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were…