CWE-647
CVEs classified under CWE-647, newest first.
6 CVEsRSS
CVE-2026-73551Medium· 5.3Envoy is an open source edge and service proxy designed for cloud-native applications
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon para…
▾ Sunlitenvoyproxy · envoyvia NVD
GHSA-c534-2w9c-x7fmMedium· 6.5Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
▾ Sunlitzxh326 · github.com/zxh326/kitevia GHSA
CVE-2026-8384Medium· 5.3Eclipse Jetty: Path parameter traversal
Eclipse Jetty: Path parameter traversal
▾ Sunliteclipse · org.eclipse.jetty:jetty-utilEPSS 0.33%via GHSA
CVE-2026-59731High· 8.2Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
▾ Twilightastro · astroEPSS 0.47%via GHSA
CVE-2026-62685High· 8.1File Browser: Colliding username normalization gives two users the same home directory
File Browser: Colliding username normalization gives two users the same home directory
▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.55%via GHSA
CVE-2026-5222LowCargo can be coerced to share credentials between registries
Cargo can be coerced to share credentials between registries
▾ Sunlitcargo · cargoEPSS 0.48%via GHSA