Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal ...
@fastify/static vulnerable to route guard bypass via encoded path separators
Hono: Arbitrary file access via serveStatic vulnerability
@fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
Fastify Middie Middleware Path Bypass
Improper Handling of URL Encoding (Hex Encoding) in GitLab
QTS, QuTS hero
Access rules for PingAccess may be circumvented with URL-encoded characters
A flaw was found in Ceph, relating to the URL processing on RGW backends
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL u...
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded