The product does not properly handle when all or part of an input has been URL encoded.
Volume of CVEs assigned to CWE-177 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59083CRITICAL Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apac | Jul 14, 2026 | 9.1 | 43 | NO | NO |
CVE-2026-41041CRITICAL URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: from 1.0.0 before 1.2.1.
Users are recommended | Jul 13, 2026 | 9.1 | 41 | NO | NO |
CVE-2026-29045CRITICAL Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protectio | Mar 4, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-22031HIGH @fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware regist | Jan 19, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-22037HIGH The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with | Jan 19, 2026 | 8.4 | 27 | NO | NO |
CVE-2022-27780HIGH The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it i | Jun 2, 2022 | 7.5 | 26 | NO | NO |
CVE-2026-6414MEDIUM @fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. Th | Apr 16, 2026 | 5.9 | 23 | NO | NO |
CVE-2022-3854MEDIUM A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of s | Mar 6, 2023 | 6.5 | 21 | NO | NO |
CVE-2018-3718MEDIUM serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded. | Jun 7, 2018 | 5.3 | 19 | NO | NO |
CVE-2024-23983MEDIUM Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules. | Nov 11, 2024 | 5.8 | 18 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.