CWE-178: Improper Handling of Case Sensitivity
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
67 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-43513 — Apache Tomcat: LockOutRealm treats user names as case-sensitive
- CVE-2025-67718 — Formio improperly authorized permission elevation through specially crafted request path
- CVE-2026-47323 — Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
- CVE-2026-28292 — simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCE
- CVE-2025-59944 — Cursor IDE: Sensitive File Overwrite Bypass is Possible
- CVE-2026-78959 — Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker le
- CVE-2026-53595 — FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
- CVE-2026-72836 — FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
- CVE-2026-32939 — DataEase is Vulnerable to H2 JDBC RCE Bypass
- CVE-2026-82067 — Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
- CVE-2024-23331 — Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
- CVE-2026-53721 — Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
- CVE-2026-62230 — Grav < 2.0.4 File Access Bypass via Case Variation
- CVE-2026-83612 — xmldom: HTML raw-text closing-tag case mismatch causes output amplification
- CVE-2026-59335 — Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA Compromise
- CVE-2026-46392 — HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validation
- CVE-2026-22665 — prompts.chat Identity Confusion via Case-Sensitive Username Handling
- CVE-2026-86770 — Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
- CVE-2025-61593 — Cursor CLI Agent: Sensitive File Overwrite Bypass
- CVE-2026-73270 — httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
Recently published
- CVE-2026-87876 — Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up)
- CVE-2026-86770 — Snipe-IT before 8.7.0 Authentication Bypass via SAML Username Collation
- CVE-2026-82067 — Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
- CVE-2021-48006 — PocketMine-MP before 4.0.3 Operator Privilege Escalation via Case Sensitivity
- CVE-2026-84428 — fastify vulnerable to header validation bypass via incomplete schema case normalization
- CVE-2026-73476 — External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098
- CVE-2026-84303 — gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
- CVE-2026-73270 — httpd mod_auth directory protection bypassed by request path casing on case-insensitive filesystems
- CVE-2026-83612 — xmldom: HTML raw-text closing-tag case mismatch causes output amplification
- CVE-2026-82726 — AshPhoenix get_subdomain maps a crafted or differently-cased Host header to an arbitrary tenant
- CVE-2026-78959 — Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker le
- CVE-2026-59335 — Case-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA Compromise
- CVE-2026-62673 — Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
- CVE-2026-72836 — FileBrowser before 2.63.19 Case Sensitivity Authentication Bypass
- CVE-2026-73416 — jupyterlab: PyPI extension blocklist package-name canonicalization bypass
- CVE-2026-72721 — Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison
- CVE-2026-71315 — Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
- CVE-2026-66883 — Oidcc.Plug.Authorize user agent session binding inert due to case-sensitive header lookup
- CVE-2026-53595 — FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
- CVE-2026-62230 — Grav < 2.0.4 File Access Bypass via Case Variation