CWE-647: Use of Non-Canonical URL Paths for Authorization Decisions
The product defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization.
12 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-80515 — In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST e
- CVE-2025-64500 — Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
- CVE-2026-59731 — Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
- CVE-2026-62685 — File Browser: Colliding username normalization gives two users the same home directory
- CVE-2025-9909 — Aap-gateway: improper path validation in gateway allows credential exfiltration
- CVE-2025-66202 — Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
- CVE-2026-15970 — L7 intention authorization bypass via custom public listener
- CVE-2026-8384 — In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:
- CVE-2025-47241 — In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be pla
- CVE-2025-43916 — Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use
- CVE-2026-5222 — Cargo can be coerced to share credentials between registries
Recently published
- CVE-2026-80515 — In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST e
- CVE-2026-15970 — L7 intention authorization bypass via custom public listener
- CVE-2026-62685 — File Browser: Colliding username normalization gives two users the same home directory
- CVE-2026-8384 — In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of:
- CVE-2026-59731 — Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
- CVE-2026-5222 — Cargo can be coerced to share credentials between registries
- CVE-2025-9909 — Aap-gateway: improper path validation in gateway allows credential exfiltration
- CVE-2025-66202 — Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
- CVE-2025-64500 — Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
- CVE-2025-47241 — In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be pla
- CVE-2025-43916 — Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing use