CVE-2026-22037: Raw Url Assignment Without Decodingcve-2026-22037-raw-url-assignment-without-decoding
Reassigning a raw, undecoded URL to the request object in a framework integration may create a parsing differential routing bypass if downstream routers expect a decoded path but native handlers decode it independently.