VulnSea

CWE-551

CVEs classified under CWE-551, newest first.

12 CVEsRSS

CVE-2026-87743High· 7.5
3d ago

A flaw was found in Quarkus HTTP security

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the secu…

TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.43%via NVD
CVE-2026-89060High· 7.7
1w ago

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…

TwilightRed Hat · multicluster-observability-addonEPSS 0.23%via NVD
CVE-2026-15573High· 8.1
1mo ago

A flaw was found in Keycloak's Authorization Services

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing…

Twilightredhat · build_of_keycloakEPSS 0.32%via NVD
CVE-2026-13676High· 7.5
2mo ago

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its…

Twilightopenjsf · fast-uriEPSS 0.48%via NVD
CVE-2026-57920High· 7.7
2mo ago

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

Twilightpeplink · intcontrol_2EPSS 0.38%via NVD
CVE-2026-50559High· 7.5
3mo ago

Quarkus is a Java framework for building cloud-native applications

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolo…

Twilightquarkus · quarkusEPSS 0.67%via NVD
CVE-2026-44575High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access throug…

Twilightvercel · next.jsEPSS 1.6%via NVD
CVE-2026-44574High· 8.1
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deploy…

Twilightvercel · next.jsEPSS 0.64%via NVD
CVE-2026-44573High· 7.5
4mo ago

Next.js is a React framework for building full-stack web applications

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized acc…

Twilightvercel · next.jsEPSS 0.62%via NVD
CVE-2026-39852High· 8.2
4mo ago

Quarkus is a Java framework for building cloud-native applications

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allo…

Twilightquarkus · quarkusEPSS 0.48%via NVD
CVE-2026-28808Critical· 9.8
5mo ago

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside Docum…

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside Docum…

Midnighterlang · erlang/inetsEPSS 0.56%via NVD
CVE-2026-33186Critical· 9.1PoC
6mo ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…

Abyssalgrpc · grpcEPSS 1.6%via NVD
CWE-551 vulnerabilities (CVEs) · VulnSea