CWE-178

Improper Handling of Case Sensitivity

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

86 vulnerabilities with CWE-178
CVE-2026-15617 CRITICAL
Logto - Principal/domain Lookup Without Case Normalization
CVSS 9.1
CVE-2026-53595 CRITICAL
FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL
CVSS 9.4
CVE-2026-62230 HIGH
Grav < 2.0.4 File Access Bypass via Case Variation
CVSS 7.5
CVE-2026-55170 MEDIUM
OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisions
CVSS 5.4
CVE-2026-54528 HIGH
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
CVSS 7.1
CVE-2026-54763 CRITICAL
Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
CVSS 10.0
CVE-2026-14617 LOW
NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity
CVSS 3.1
CVE-2026-58057 MEDIUM
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
CVSS 5.0
CVE-2026-57234 LOW
Nokogiri JRuby < 1.19.4 - NONET Bypass Allows Network Requests
CVSS 2.6
CVE-2026-45135 HIGH
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
CVSS 8.1
CVE-2026-48794 LOW
Authelia has an Edge Case Access Control Rule Mismatch
CVE-2026-47203 LOW
Authelia Missing Username Canonicalization in Basic Auth (LDAP)
CVE-2026-49336 MEDIUM
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
CVE-2026-53721 HIGH
Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher
CVSS 8.2
CVE-2026-45062 HIGH
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
CVSS 8.1
CVE-2026-47346 HIGH
TYPO3 CMS - Broken Access Control in Form Framework
CVE-2026-46392 HIGH
HAX CMS PHP <26.0.0 HTML Upload Validation - Stored Cross-Site Scripting
CVSS 8.7
CVE-2026-8404 LOW
Potential exposure of private data via case-sensitive Cache-Control directives in UpdateCacheMiddleware
CVSS 3.1
CVE-2026-48595 HIGH
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
CVE-2026-44367 LOW
Klaw: user lockout due to case sensitivity inconsistency
CVSS 2.7
CVE-2026-47323 CRITICAL
Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering
CVSS 9.8
CVE-2026-43513 HIGH
Apache Tomcat: LockOutRealm treats user names as case-sensitive
CVSS 7.5
CVE-2026-42273 HIGH
Heimdall: Case-sensitive host matching may lead to policy bypass
CVE-2026-42272 HIGH
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
CVE-2026-3833 MEDIUM
Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
CVSS 6.5
Details
Vulnerabilities 86