URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @f
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/expr
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and form
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never
Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin mid
@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution,
Frequently Asked Questions
What is CWE-177?
CWE-177 (CWE-177) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-177?
There are 9 CVE records associated with CWE-177 in our database. Of these, 2 are critical severity, 5 are high severity, and 2 are medium severity.
How can I protect against CWE-177 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-177 using AI-powered security agents.
Detect CWE-177 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-177 vulnerabilities across your infrastructure.
Get Started