The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.
Volume of CVEs assigned to CWE-180 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39364HIGH Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt | Apr 7, 2026 | 7.5 | 42 | NO | YES |
CVE-2026-52747HIGH ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmo | Jul 10, 2026 | 8.6 | 41 | NO | NO |
CVE-2026-49984HIGH Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before | Jun 26, 2026 | 7.7 | 36 | NO | NO |
CVE-2026-34475CRITICAL Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cac | Mar 27, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-48721HIGH Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the d | Jun 24, 2026 | 8.6 | 34 | NO | NO |
CVE-2022-26136CRITICAL A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which f | Jul 20, 2022 | 9.8 | 34 | NO | NO |
CVE-2026-27590CRITICAL Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the | Feb 24, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-42462HIGH Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of | Jun 10, 2026 | 7.0 | 31 | NO | NO |
CVE-2026-24895CRITICAL FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic co | Feb 12, 2026 | 9.8 | 31 | NO | NO |
CVE-2022-26137HIGH A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests o | Jul 20, 2022 | 8.8 | 29 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.