CWE-44Variant1 in KEV

Path Equivalence: 'file.name' (Internal Dot)

Incomplete in the CWE catalog · 1 CVE mapped

1
CVEs mapped
1
In KEV
10.0
Median CVSS
What it is

The product accepts path input in the form of internal dot ('file.ordir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

Recent examples
10.0cvss
CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

🚨 A sneaky path equivalence flaw in Apache Tomcat could let attackers execute code remotely or access sensitive files, all thanks to a default servlet that might be too trusting! 🔥 Think of it like a restaurant kitchen where the chef can accidentally serve up a confidential recipe if the delivery driver misplaces the order — if no one checks, anyone could gain access to secret ingredients! If exploited, an attacker could not only view sensitive files but also sneak in malicious content or even take over the server entirely. This could lead to absolute chaos, from data breaches to full remote control of your applications. It's a nightmare scenario that no one wants to face!

KEV · OVERDUECRITICAL
100%
epss
The record
Technical detail
CWE ID
CWE-44
Abstraction
Variant
Structure
Simple
Status
Incomplete