CWE-436
Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
126 vulnerabilities with CWE-436
CVE-2026-42274
HIGH
Heimdall: Authorization bypass via path normalization mismatch
CVE-2026-42273
HIGH
Heimdall: Case-sensitive host matching may lead to policy bypass
CVE-2026-42272
HIGH
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
CVE-2026-8034
CRITICAL
Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via URL parser confusion
CVSS 9.8
CVE-2026-30246
MEDIUM
github.com/gofiber/fiber/v3 cache middleware can mix responses across query parameters
CVSS 6.5
CVE-2026-6322
HIGH
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
CVSS 7.5
CVE-2026-41248
CRITICAL
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
CVSS 9.1
CVE-2026-33804
HIGH
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
CVSS 7.4
CVE-2026-6270
CRITICAL
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
CVSS 9.1
CVE-2026-33808
CRITICAL
@fastify/express vulnerable to middleware authentication bypass via URL normalization gaps (duplicate slashes and semicolons)
CVSS 9.1
CVE-2026-33807
CRITICAL
@fastify/express vulnerable to middleware path doubling causing authentication bypass in child plugin scopes
CVSS 9.1
CVE-2026-35200
MEDIUM
Parse Server File Uploads - Content-Type Override
CVSS 5.4
CVE-2026-32762
MEDIUM
Rack: Forwarded Header semicolon injection enables Host and Scheme spoofing
CVSS 4.8
CVE-2026-26961
LOW
Rack: Multipart Boundary Parsing Ambiguity allowing WAF Bypass
CVSS 3.7
CVE-2026-32065
MEDIUM
OpenClaw < 2026.2.25 - Approval Identity Mismatch in system.run Command Execution
CVSS 4.8
CVE-2026-32052
MEDIUM
OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers
CVSS 6.4
CVE-2026-32766
MEDIUM
astral-tokio-tar insufficiently validates PAX extensions during extraction
CVSS 5.3
CVE-2026-27444
HIGH
SEPPmail Secure Email Gateway <15.0.1 - Auth Bypass
CVSS 7.5
CVE-2026-27896
HIGH
modelcontextprotocol/go-sdk < 1.3.1 - JSON-RPC Field Case Sensitivity Bypass via Non-Standard Casing
CVSS 7.5
CVE-2026-0958
HIGH
GitLab 18.4-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Unauthenticated Denial of Service via JSON Validation Middleware Bypass
CVSS 7.5
CVE-2026-23686
LOW
SAP NetWeaver Application Server Java - CRLF Injection
CVSS 3.4
CVE-2026-25223
HIGH
fastify < 5.7.2 - Request Body Validation Bypass via Content-Type Header Tab Injection
CVSS 7.5
CVE-2025-66490
MEDIUM
Traefik < 2.11.32 and 3.0.0-3.6.2 - Path Normalization Bypass via URL-Encoded Characters
CVSS 6.5
CVE-2025-12816
HIGH
node-forge < 1.3.2 - Unauthenticated ASN.1 Interpretation Conflict via Schema Desynchronization
CVSS 8.6
CVE-2025-54368
MEDIUM
Pypi UV < 0.8.6 - Interpretation Conflict
Details
Vulnerabilities
126