Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such a
`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request ma
Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request ma
Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unaut
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFi
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint i
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4
Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules
DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handlin
prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive an
FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP
A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistent
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership duri
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prio
Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, ther
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat:
Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access t
JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandl
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewal
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra
Improper handling of case sensitivity in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker le
Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party ori
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the dat
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparis
Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function Gatewa
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability ex
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F
@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o
Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules
Frequently Asked Questions
What is CWE-178?
CWE-178 (CWE-178) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-178?
There are 49 CVE records associated with CWE-178 in our database. Of these, 8 are critical severity, 16 are high severity, and 9 are medium severity.
How can I protect against CWE-178 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-178 using AI-powered security agents.
Detect CWE-178 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-178 vulnerabilities across your infrastructure.
Get Started