VYPR

CWE-41

Improper Resolution of Path Equivalence

BaseIncomplete

Description

The product is vulnerable to file system contents disclosure through path equivalence. Path equivalence involves the use of special characters in file and directory names. The associated manipulations are intended to generate multiple names for the same object.

Path equivalence is usually employed in order to circumvent access controls expressed using an incomplete set of file name or file path representations. This is different from path traversal, wherein the manipulations are performed to generate a name for a different object.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-3

CVEs mapped to this weakness (34)

page 2 of 2
  • CVE-2024-6839MedMar 20, 2025
    risk 0.28cvss 5.3epss 0.01

    corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This…

  • CVE-2025-21247MedMar 11, 2025
    risk 0.28cvss 4.3epss 0.03

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2025-21332MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.01

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21329MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.02

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21328MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.02

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21269MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.05

    Windows HTML Platforms Security Feature Bypass Vulnerability

  • CVE-2025-21268MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.02

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21219MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.03

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2025-21189MedJan 14, 2025
    risk 0.28cvss 4.3epss 0.03

    MapUrlToZone Security Feature Bypass Vulnerability

  • CVE-2026-66064MedJul 28, 2026
    risk 0.27cvss 5.3epss 0.00

    goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs…

  • CVE-2026-34510MedApr 1, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content,…

  • CVE-2025-58290LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-50568LowJun 10, 2026
    risk 0.16cvss 3.6epss 0.00

    Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling…

  • CVE-2022-0855MedMar 4, 2022
    risk 0.00cvss 6.1epss 0.01

    Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.