CWE-647

CWE-647 · 3 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-647, highest CVSS first.

  1. MEDIUM 5.3CVE-2026-73551public PoC

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon parameters. A request such …

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.7CVE-2026-71178

    Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, l…

    policy manager for secure connect gateway

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-94269

    Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were…

    AI risk analysis on Exploit-DB.ai →