CVE-2026-48599: Insecure Map Merge Path Precedence
Merging path parameters with query or body parameters such that path parameters serve as the base map in `Map.merge/2`. In Elixir, `Map.merge/2` overwrites keys in the first map with keys from the second map. This allows untrusted user inputs from queries or request bodies to overwrite path-extracted variables, which can lead to Authorization Bypass or Insec
greprules fetch cve-2026-48599-insecure-map-merge-path-precedence --engine opengrepDescription
Merging path parameters with query or body parameters such that path parameters serve as the base map in `Map.merge/2`. In Elixir, `Map.merge/2` overwrites keys in the first map with keys from the second map. This allows untrusted user inputs from queries or request bodies to overwrite path-extracted variables, which can lead to Authorization Bypass or Insec
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.