CWE-180: Incorrect Behavior Order: Validate Before Canonicalize
The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.
28 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-39364 — Vite has a `server.fs.deny` bypass with queries
- CVE-2026-24895 — FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary files
- CVE-2026-15704 — CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
- CVE-2026-73420 — NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
- CVE-2026-82481 — The cohttp package before 6.3.0 for OCaml allows directory traversal.
- CVE-2025-29787 — zip Vulnerable to Incorrect Path Canonicalization During Archive Extraction, Leading to Arbitrary File Write
- CVE-2026-52747 — ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
- CVE-2026-48721 — Warp: Env-var prefixes can lead to denylisted command autoexecution
- CVE-2026-49984 — Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)
- CVE-2026-62999 — Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (Incomplete fix for trust-prefix bypass)
- CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks
- CVE-2026-45022 — go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
- CVE-2026-42462 — Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
- CVE-2025-43716 — A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to
- CVE-2025-33194 — NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of i
- CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope
- CVE-2026-34475 — Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle UR
- CVE-2026-34786 — Rack: Rack::Static header_rules bypass via URL-encoded paths
- CVE-2026-39409 — Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
- CVE-2026-73416 — jupyterlab: PyPI extension blocklist package-name canonicalization bypass
Recently published
- CVE-2026-82736 — Ash.Type.CiString validates length and match constraints before case folding, allowing constraint bypass
- CVE-2026-82481 — The cohttp package before 6.3.0 for OCaml allows directory traversal.
- CVE-2026-76203 — CSS sanitizer bypass in Pentestify report themes allows forced outbound requests
- CVE-2026-73416 — jupyterlab: PyPI extension blocklist package-name canonicalization bypass
- CVE-2026-73420 — NextAuth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
- CVE-2026-72917 — AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization
- CVE-2026-69246 — Guzzle: Noncanonical host can bypass host-based checks
- CVE-2026-69245 — Guzzle: Noncanonical cookie domain keeps subdomain scope
- CVE-2026-62999 — Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (Incomplete fix for trust-prefix bypass)
- CVE-2026-15704 — CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components
- CVE-2026-7120 — @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
- CVE-2026-52747 — ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass
- CVE-2026-49984 — Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)
- CVE-2026-48721 — Warp: Env-var prefixes can lead to denylisted command autoexecution
- CVE-2026-42462 — Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring
- CVE-2026-45022 — go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
- CVE-2026-39409 — Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
- CVE-2026-39364 — Vite has a `server.fs.deny` bypass with queries
- CVE-2026-34786 — Rack: Rack::Static header_rules bypass via URL-encoded paths
- CVE-2026-34475 — Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle UR