Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
4797
Downloads
6.6M
Verified
4797
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2026-47676: Unsafe Url Pathname Slicecve-2026-47676-unsafe-url-pathname-slice

Directly slicing `url.pathname` with a dynamically calculated index length can result in arbitrary path truncation when requests contain percent-encoded multibyte characters. Because multi-byte characters require more string characters when percent-encoded, a length calculated from a decoded representation will misalign with the encoded representation, causi

by Provallyupdated 2026-06-12Apache-2.0
2.2K0 direct2.2K via packs
downloads
73quality
All matching rules loaded.