VulnSea

CWE-647

CVEs classified under CWE-647, newest first.

6 CVEsRSS

CVE-2026-73551Medium· 5.3
yesterday

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon para…

Sunlitenvoyproxy · envoyvia NVD
GHSA-c534-2w9c-x7fmMedium· 6.5
2mo ago

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

Sunlitzxh326 · github.com/zxh326/kitevia GHSA
CVE-2026-8384Medium· 5.3
2mo ago

Eclipse Jetty: Path parameter traversal

Eclipse Jetty: Path parameter traversal

Sunliteclipse · org.eclipse.jetty:jetty-utilEPSS 0.33%via GHSA
CVE-2026-59731High· 8.2
2mo ago

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

Twilightastro · astroEPSS 0.47%via GHSA
CVE-2026-62685High· 8.1
2mo ago

File Browser: Colliding username normalization gives two users the same home directory

File Browser: Colliding username normalization gives two users the same home directory

Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA
CVE-2026-5222Low
2mo ago

Cargo can be coerced to share credentials between registries

Cargo can be coerced to share credentials between registries

Sunlitcargo · cargoEPSS 0.48%via GHSA
CWE-647 vulnerabilities (CVEs) · VulnSea