CWE-177: Hex Encoding
The product does not properly handle when all or part of an input has been URL encoded.
15 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-59083 — Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
- CVE-2026-22037 — @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
- CVE-2026-22031 — Fastify Middie Middleware Path Bypass
- CVE-2026-41041 — Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
- CVE-2026-29045 — Hono: Arbitrary file access via serveStatic vulnerability
- CVE-2026-15371 — Velociraptor Stored XSS in URL column types
- CVE-2026-76172 — fast-uri vulnerable to host confusion via percent-encoded scheme normalization
- CVE-2024-23983 — Access rules for PingAccess may be circumvented with URL-encoded characters
- CVE-2026-67448 — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
- CVE-2026-6414 — @fastify/static vulnerable to route guard bypass via encoded path separators
- CVE-2025-11990 — Improper Handling of URL Encoding (Hex Encoding) in GitLab
- CVE-2024-48866 — QTS, QuTS hero
Recently published
- CVE-2026-76172 — fast-uri vulnerable to host confusion via percent-encoded scheme normalization
- CVE-2026-67448 — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
- CVE-2026-15371 — Velociraptor Stored XSS in URL column types
- CVE-2026-59083 — Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
- CVE-2026-41041 — Apache Gravitino: URL path injection via unencoded user-supplied identifiers in MCP REST client f-string URL construction, enabling path traversal to unintended API endpoints.
- CVE-2026-6414 — @fastify/static vulnerable to route guard bypass via encoded path separators
- CVE-2026-29045 — Hono: Arbitrary file access via serveStatic vulnerability
- CVE-2026-22037 — @fastify/express vulnerable to Improper Handling of URL Encoding (Hex Encoding)
- CVE-2026-22031 — Fastify Middie Middleware Path Bypass
- CVE-2025-11990 — Improper Handling of URL Encoding (Hex Encoding) in GitLab
- CVE-2024-48866 — QTS, QuTS hero
- CVE-2024-23983 — Access rules for PingAccess may be circumvented with URL-encoded characters