CVE-2026-49846
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".." sequences intact, enabling path traversal in any consumer that later joins the URI with a filesystem path. Version 2.0.11 patches the issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-22, CWE-697
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- signalwire libks
Weakness type
Related vulnerabilities
- CVE-2026-85706 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2026-90445 — An interface that accepts file uploads from authenticated users extracts the contents of uploaded...
- CVE-2026-87910 — tarfile hardlink fallback ignores custom extraction filter rejection via None
- CVE-2026-87984 — An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an...
- CVE-2026-87983 — An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an...
- CVE-2026-87727 — a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an...
- CVE-2026-19991 — UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion
- CVE-2026-77807 — AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter