CWE-551: Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
If a web server does not fully parse requested URLs before it examines them for authorization, it may be possible for an attacker to bypass authorization protection.
15 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2023-23924 — URI validation failure on SVG parsing in Dompdf
- CVE-2021-34429 — For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
- CVE-2021-28164 — In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai
- CVE-2021-28165 — In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re
- CVE-2016-20030 — ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction
- CVE-2023-6394 — Quarkus: graphql operations over websockets bypass
- CVE-2021-31384 — Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the service
- CVE-2021-32779 — Incorrectly handling of URI '#fragment' element as part of the path element
- CVE-2021-32777 — Incorrect concatenation of multiple value request headers in ext-authz extension
- CVE-2026-4636 — Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
- CVE-2026-16102 — Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
- CVE-2026-15573 — Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
- CVE-2026-89060 — Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references
- CVE-2026-57920 — Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai
- CVE-2026-0707 — Keycloak: keycloak authorization header parsing leading to potential security control bypass
Recently published
- CVE-2026-89060 — Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references
- CVE-2026-16102 — Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
- CVE-2026-15573 — Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
- CVE-2026-57920 — Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai
- CVE-2026-4636 — Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized access to victim-owned resources.
- CVE-2016-20030 — ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction
- CVE-2026-0707 — Keycloak: keycloak authorization header parsing leading to potential security control bypass
- CVE-2023-6394 — Quarkus: graphql operations over websockets bypass
- CVE-2023-23924 — URI validation failure on SVG parsing in Dompdf
- CVE-2021-31384 — Junos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the service
- CVE-2021-32779 — Incorrectly handling of URI '#fragment' element as part of the path element
- CVE-2021-32777 — Incorrect concatenation of multiple value request headers in ext-authz extension
- CVE-2021-34429 — For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
- CVE-2021-28165 — In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re
- CVE-2021-28164 — In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai