CWE-706
Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
116 vulnerabilities with CWE-706
CVE-2026-16120
MEDIUM
nextlevelbuilder GoClaw exec_approval.go extractBin name resolution
CVSS 6.3
CVE-2026-62685
HIGH
File Browser: Colliding username normalization gives two users the same home directory
CVSS 8.1
CVE-2026-62190
HIGH
OpenClaw < 2026.6.9 Authorization Bypass via flock wrapper
CVSS 8.8
CVE-2026-57054
MEDIUM
Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs
CVSS 5.8
CVE-2026-13372
HIGH
Devolutions Remote Desktop Manager < 2026.2.11 - Use of Incorrectly-Resolved Name or Reference
CVSS 7.2
CVE-2026-54022
MEDIUM
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
CVSS 5.3
CVE-2026-54282
LOW
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVSS 3.7
CVE-2026-10696
HIGH
Devolutions UniGetUI < 2026.2.1 - Use of Incorrectly-Resolved Name or Reference
CVSS 7.5
CVE-2026-45306
MEDIUM
pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory
CVSS 6.5
CVE-2026-8716
MEDIUM
Use of Incorrectly-Resolved Name or Reference in GitLab
CVSS 4.3
CVE-2026-40912
HIGH
Traefik: StripPrefixRegex auth bypass via Path/RawPath desync
CVSS 8.2
CVE-2026-41402
MEDIUM
OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass
CVSS 4.2
CVE-2026-42254
MEDIUM
Hickory DNS 0.1-0.25.2 - Cross-Zone Poisoning
CVSS 4.0
CVE-2026-41354
LOW
OpenClaw < 2026.4.2 - Insufficient Scope in Zalo Webhook Replay Dedupe Keys
CVSS 3.7
CVE-2026-35358
MEDIUM
uutils coreutils cp Semantic Loss and Potential Denial of Service with -R via Device Node Stream Reading
CVSS 4.4
CVE-2026-41131
MEDIUM
OpenFGA has Improper Policy Enforcement
CVSS 5.0
CVE-2026-35666
HIGH
OpenClaw < 2026.3.22 - Allowlist Bypass via Unregistered Time Dispatch Wrapper
CVSS 8.8
CVE-2026-35635
MEDIUM
OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat
CVSS 4.8
CVE-2026-35039
CRITICAL
fast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)
CVSS 9.1
CVE-2026-33732
MEDIUM
srvx is vulnerable to middleware bypass via absolute URI in request line
CVSS 4.8
CVE-2026-33490
LOW
h3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching Routes
CVSS 3.7
CVE-2026-1230
MEDIUM
GitLab 18.7.5/18.8.5/18.9.1 - Authenticated Repository Content Spoofing via Branch Reference Validation Bypass
CVSS 4.1
CVE-2026-30856
MEDIUM
Tencent WeKnora < 0.3.0 - Indirect Prompt Injection via MCP Tool Name Collision
CVSS 5.9
CVE-2026-3125
MEDIUM
@opennextjs/cloudflare < 1.17.1 - Server-Side Request Forgery via Path Normalization Bypass
CVSS 6.5
CVE-2026-25890
HIGH
filebrowser < 2.57.1 - Authenticated Authorization Bypass via Multiple Slash Path Manipulation
CVSS 8.1
Details
Vulnerabilities
116