Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-647

Use of Non-Canonical URL Paths for Authorization Decisions

The product defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization.

10
Assigned CVEs
435th
Commonality Rank
6.6
Avg CVSS
10.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-647 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2023
3 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-43939CRITICAL
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumven
Apr 3, 20239.899YESYES
CVE-2025-64500HIGH
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP s
Nov 12, 20257.339NOYES
CVE-2026-59731HIGH
Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit,
Jul 8, 20268.235NONO
CVE-2026-62685HIGH
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new u
Jul 15, 20268.134NONO
CVE-2026-5222MEDIUM
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hoste
May 25, 20266.532NONO
CVE-2026-8384MEDIUM
In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expe
Jul 14, 20265.330NONO
CVE-2025-9909MEDIUM
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using
Feb 27, 20266.723NONO
CVE-2025-66202MEDIUM
Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro
Dec 9, 20256.523NONO
CVE-2025-47241MEDIUM
In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.
May 3, 20254.018NONO
CVE-2025-43916LOW
Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent wi
Apr 21, 20253.414NONO
View all 10 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
10%
3.0-3.9
10%
10%
4.0-4.9
10%
19%
5.0-5.9
30%
16%
6.0-6.9
10%
26%
7.0-7.9
20%
11%
8.0-8.9
10%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
10.0% of CVEs· 99th percentile
Metasploit
1 CVE
10.0% of CVEs· 98th percentile
Nuclei
2 CVEs
20.0% of CVEs· 99th percentile
ExploitDB
1 CVE
10.0% of CVEs· 97th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products