{"id":"CVE-2026-95811","summary":"Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it","details":"Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it.\n\nThe handler matches each vhost's locationRules regular expressions against REQUEST_URI, the raw request line, while the web server routes on the path it has already percent-decoded and normalized. A request that percent-encodes a character of the path, inserts dot segments, or doubles a slash therefore reaches the protected resource under a URI that no rule regexp matches, and the vhost's default rule decides access. Deny rules, identity and group conditions, and unprotect and skip rules are bypassed alike.\n\nOnly a vhost whose default rule is more permissive than its other rules is affected. An authenticated user then reaches any URL a locationRules regexp was meant to restrict, but gains no more than that default rule already grants.","modified":"2026-09-28T03:48:35.830660563Z","published":"2026-09-25T01:31:22.472Z","database_specific":{"cwe_ids":["CWE-180","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95811.json","cna_assigner":"CPANSec"},"references":[{"type":"WEB","url":"https://cpan.org/modules"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/09/msg00032.html"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2020-24660"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/95xxx/CVE-2026-95811.json"},{"type":"ADVISORY","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.16.10"},{"type":"ADVISORY","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.21.6"},{"type":"ADVISORY","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/releases/v2.23.4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95811"},{"type":"REPORT","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/issues/3723"},{"type":"PACKAGE","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng"},{"type":"EVIDENCE","url":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3723"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng","events":[{"introduced":"ea90c3c77f2e01b36f2391a1d07542b359af3d70"},{"fixed":"b2723222e4a2df1ca010fb5d4253a595a25d6e5f"},{"introduced":"90a97ab1d90f1d32eaf56d0e4f3a72ca7cb40877"},{"fixed":"648024b3b5c61410018fa2830b99a33d5fd72a83"},{"introduced":"508741c39bcdbb51b8345749fcf4bfa337dba420"},{"fixed":"6602ae87a262e28539d54454ec99622c75141cb5"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.16.10"},{"introduced":"2.17.0"},{"fixed":"2.21.6"},{"introduced":"2.22.0"},{"fixed":"2.23.4"}]}}],"versions":["v2.21.5","v2.16.9","v2.23.3","v2.23.2","v2.23.1","v2.23.0","v2.16.8","v2.21.4","v2.21.3","v2.22.0","v2.16.7","v2.16.6","v2.21.2","v2.21.1","v2.16.5","v2.21.0","v2.16.4","v2.20.0","v2.19.0","v2.16.3","v2.18.1","v2.18.0","v2.0.2","ubuntu/disco","debian/buster","v2.0.11","ubuntu/hirsute","debian/bullseye","v2.17.0","v2.16.2","v2.16.1","debian/bookworm","v2.0.15.1","v2.0.15","v2.0.14","v2.0.13","ubuntu/jammy","v2.0.12","v2.0.10","v2.0.9","v2.0.8","ubuntu/groovy","v2.0.7","ubuntu/focal","v2.0.6","v2.0.4","v2.0.3","v2.0.1","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-95811.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}