Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-177

Improper Handling of URL Encoding (Hex Encoding)

The product does not properly handle when all or part of an input has been URL encoded.

12
Assigned CVEs
407th
Commonality Rank
7.1
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-177 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2018
8 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-59083CRITICAL
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apac
Jul 14, 20269.143NONO
CVE-2026-41041CRITICAL
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended
Jul 13, 20269.141NONO
CVE-2026-29045CRITICAL
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protectio
Mar 4, 20269.832NONO
CVE-2026-22031HIGH
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware regist
Jan 19, 20268.828NONO
CVE-2026-22037HIGH
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with
Jan 19, 20268.427NONO
CVE-2022-27780HIGH
The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it i
Jun 2, 20227.526NONO
CVE-2026-6414MEDIUM
@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. Th
Apr 16, 20265.923NONO
CVE-2022-3854MEDIUM
A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of s
Mar 6, 20236.521NONO
CVE-2018-3718MEDIUM
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Jun 7, 20185.319NONO
CVE-2024-23983MEDIUM
Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.
Nov 11, 20245.818NONO
View all 12 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
8%
3.0-3.9
10%
4.0-4.9
33%
19%
5.0-5.9
8%
16%
6.0-6.9
8%
26%
7.0-7.9
17%
11%
8.0-8.9
25%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products