VulnSea

CWE-178

CVEs classified under CWE-178, newest first.

42 CVEsRSS

GHSA-8678-w3jw-xfc2Low· 2.6
3mo ago

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Sunlitnokogiri · nokogirivia GHSA
CVE-2026-54528High· 7.1
3mo ago

jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories

jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories

Twilightjupyterlab-git · jupyterlab-gitEPSS 0.41%via GHSA
GHSA-j99q-93c9-h869Medium
3mo ago

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
CVE-2026-55170Low
3mo ago

OpenFGA Improper Policy Enforcement

OpenFGA Improper Policy Enforcement

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.34%via GHSA
CVE-2026-53721High
3mo ago

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher

Twilightnuxt · nuxtEPSS 0.40%via GHSA
CVE-2026-47346High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

Twilighttypo3 · typo3/cms-coreEPSS 0.25%via GHSA
CVE-2026-3833Medium· 6.5PoC
4mo ago

A flaw was found in gnutls

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `perm…

Twilightgnu · gnutlsEPSS 0.56%via NVD
CVE-2026-40453Critical· 9.9PoC
4mo ago

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) c…

AbyssalEPSS 1.6%via NVD
CVE-2026-22665High· 8.1
5mo ago

prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usern…

prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usern…

Twilightfka · prompts.chatEPSS 0.33%via NVD
CVE-2026-27896High· 7.0
6mo ago

MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagg…

Twilightmodelcontextprotocol · go-sdkEPSS 0.26%via CVEORG
CVE-2025-4035Medium· 4.3
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to be set for public suffix domains if the domain contains at least two components and includes an uppercase character. This bypasses public suf…

SunlitEPSS 0.42%via NVD
CVE-2020-12812Critical· 9.8CISA KEV
6y ago

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if t…

Hadalfortinet · fortiosEPSS 49%via NVD
CWE-178 vulnerabilities (CVEs) — page 2 · VulnSea