CWE-41
Improper Resolution of Path Equivalence
Description
The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-3
CVEs mapped to this weakness (31)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21328 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21269 | Med | 0.28 | 4.3 | 0.05 | Jan 14, 2025 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2025-21268 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21219 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21189 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2026-66064 | Med | 0.27 | 5.3 | 0.00 | Jul 28, 2026 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs… | ||
| CVE-2026-34510 | Med | 0.27 | 5.3 | 0.00 | Apr 1, 2026 | OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content,… | ||
| CVE-2026-57441 | med | 0.26 | — | — | Jun 18, 2026 | On case-insensitive filesystems (macOS, Windows), PathFilter compiled its deny-list patterns case-sensitively and matched the path verbatim, so names like `.Git/config`, `.GIT/config`, or `.oBsIdIaN/secrets.md` slipped past the `.git`/`.obsidian`/`node_modules` restriction while… | ||
| CVE-2025-58290 | Low | 0.21 | 3.3 | 0.00 | Oct 11, 2025 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-50568 | Low | 0.16 | 3.6 | 0.00 | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling… | ||
| CVE-2022-0855 | Med | 0.00 | 6.1 | 0.01 | Mar 4, 2022 | Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4. |
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.05
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.27cvss 5.3epss 0.00
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs…
- risk 0.27cvss 5.3epss 0.00
OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content,…
- risk 0.26cvss —epss —
On case-insensitive filesystems (macOS, Windows), PathFilter compiled its deny-list patterns case-sensitively and matched the path verbatim, so names like `.Git/config`, `.GIT/config`, or `.oBsIdIaN/secrets.md` slipped past the `.git`/`.obsidian`/`node_modules` restriction while…
- risk 0.21cvss 3.3epss 0.00
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- risk 0.16cvss 3.6epss 0.00
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling…
- risk 0.00cvss 6.1epss 0.01
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.