VulnSea

CWE-178

CVEs classified under CWE-178, newest first.

42 CVEsRSS

CVE-2026-77560High· 8.1
today

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…

Twilighttinyauthapp · tinyauthvia NVD
CVE-2026-77281Medium· 6.5
4d ago

Caddy is an extensible server platform that uses TLS by default

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…

Sunlitcaddyserver · caddyEPSS 0.36%via NVD
CVE-2026-90982Medium· 5.3
4d ago

@fastify/static is a Fastify plugin that serves static files from a configured root directory

@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restrict…

Sunlit@fastify/static · @fastify/staticEPSS 0.36%via NVD
CVE-2026-57441High· 8.4
6d ago

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault

MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, PathFilter in src/pathfilter.ts compiles restricted-directory patterns case-sensitively and compares paths without ca…

Twilightbitbonsai · mcpvaultEPSS 0.17%via NVD
CVE-2026-86472Medium· 4.8
6d ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the …

Sunlitfast-uri · fast-uriEPSS 0.16%via NVD
CVE-2026-54567High· 7.5PoC
1w ago

Flask-Reuploaded provides file uploads for Flask

Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension hel…

Midnightjugmac00 · flask-reuploadedEPSS 0.58%via NVD
CVE-2026-89012Medium· 6.5PoC
1w ago

Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denyl…

TwilightDolibarr · DolibarrEPSS 0.34%via CVEORG
CVE-2026-86770High· 8.1PoC
1w ago

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers c…

Midnightsnipeitapp · snipe-itEPSS 0.32%via NVD
CVE-2026-87876Low· 3.0PoC
1w ago

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

TwilightRed Hat · cups-mainEPSS 0.39%via NVD
CVE-2026-82067High· 8.1
1w ago

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state during server startup. An unauthenticated user with network acc…

Twilightmongodb · mongodbEPSS 0.28%via NVD
CVE-2021-48006Low· 3.3
2w ago

PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt

PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored …

Sunlitpmmp · PocketMine-MPEPSS 0.11%via NVD
CVE-2026-84428High· 7.5
2w ago

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and th…

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and th…

Twilightfastify · fastifyEPSS 0.30%via NVD
CVE-2026-73476Medium· 5.4
2w ago

Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation

Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.

Sunlitexternal_authentication_project · external_authenticationEPSS 0.18%via NVD
CVE-2026-84303Medium
2w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are…

Sunlitgrpc · google.golang.org/grpcEPSS 0.31%via NVD
CVE-2026-83612High
2w ago

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mode parsing through DOMParser.parseFromString() mishandles a mixed-case closing tag for the s…

Twilightxmldom · @xmldom/xmldomEPSS 0.30%via NVD
CVE-2026-73270High· 8.2
2w ago

Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose fil…

Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose fil…

TwilightErlang · otpEPSS 0.66%via NVD
CVE-2026-62673High
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On …

Twilightgetgrav · getgrav/gravEPSS 0.50%via NVD
CVE-2026-72836High· 8.1
1mo ago

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration

FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive files…

TwilightEPSS 0.41%via NVD
CVE-2026-73416Medium
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jup…

Sunlitjupyterlab · jupyterlabEPSS 0.49%via NVD
CVE-2026-72721Medium· 5.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.is_blocked? compares hostnames and SiteSetting.blocked_onebox_domains entries case-sensitively, allowing an attac…

SunlitEPSS 0.43%via NVD
CVE-2026-54763High
1mo ago

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Twilighttraefik · github.com/traefik/traefik/v2EPSS 0.21%via GHSA
CVE-2026-70429Medium· 6.5
1mo ago

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters t…

Sunlitjenkins · jenkinsEPSS 0.24%via NVD
CVE-2026-15573High· 8.1
1mo ago

A flaw was found in Keycloak's Authorization Services

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing…

Twilightredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-71315High· 8.2
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorizatio…

Twilightnuxt · nuxtEPSS 0.27%via NVD
GHSA-89vp-jrxv-24w8Medium
2mo ago

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-xrmc-c5cg-rv7xHigh· 8.8
2mo ago

SafeInstall agent guard shell parsing can miss raw package execution

SafeInstall agent guard shell parsing can miss raw package execution

Twilightsafeinstall-cli · safeinstall-clivia GHSA
CVE-2026-48595High
2mo ago

Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering

Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering

Twilighttesla · teslaEPSS 0.49%via GHSA
CVE-2026-14617Low· 3.1
2mo ago

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Ta…

SunlitEPSS 0.37%via NVD
CVE-2026-49336Medium
2mo ago

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter

Sunlitmicrosoft · @microsoft/kiota-http-fetchlibraryEPSS 1.2%via GHSA
CVE-2026-48794Low
2mo ago

Authelia has an Edge Case Access Control Rule Mismatch

Authelia has an Edge Case Access Control Rule Mismatch

Sunlitauthelia · github.com/authelia/authelia/v4EPSS 0.41%via GHSA
CWE-178 vulnerabilities (CVEs) · VulnSea