CVE-2026-27851CWE-235

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to…

High · published May 12, 2026

CVSS v3.1
7.4
EPSS
0%
Percentile
33.8
In the wild
Unconfirmed
What it is

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on fixed version. No publicly available exploits are known.

The record
Technical detail
CVSS v3.1
7.4 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00406 · 33.8th percentile
Weakness
CWE-235 · Improper Handling of Extra Parameters
Published
2026-05-12T13:28Z
EPSS history
Timeline
  • 12 MAY 13:28Z
    When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to…
    cvelistv5