Cyber Resilience

CWE · MITRE source

CWE-178Improper Handling of Case Sensitivity

Abstraction: Base · CVEs in our corpus: 94

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

Improperly handled case sensitive data can lead to several possible consequences, including:

Last updated: 22 August 2026 14:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • AC-3 Access Enforcement
  • AC-24 Access Control Decisions
  • PR.PS-06
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-12812 KEV 9.99.80.49342020-07-24
CVE-2021-24347 8.78.80.53802021-06-14
CVE-2018-9845 8.39.80.13132018-04-29
CVE-2001-0766 8.19.80.08162001-10-18
CVE-2002-1820 7.79.80.02382002-12-31
CVE-2002-2119 7.79.80.02672002-12-31
CVE-2004-2154 7.79.80.02072004-12-31
CVE-2004-2214 7.79.80.02702004-12-31
CVE-2005-0269 7.79.80.02642005-05-02
CVE-2023-3545 7.79.80.02442023-11-28
CVE-2026-28292 7.69.80.01302026-03-10
CVE-2026-47323 7.69.80.01542026-05-19
CVE-2022-29604 7.59.80.01022023-04-20
CVE-2024-5699 7.49.80.00772024-06-11
CVE-2026-40453 7.39.90.01552026-04-27
CVE-2003-0411 7.27.50.25112003-06-30
CVE-2025-27636 7.15.60.80852025-03-09
CVE-2026-547637.110.00.00212026-07-06
CVE-2021-25036 7.08.80.03032022-01-17
CVE-2026-535957.09.40.00372026-07-20
CVE-2019-6289 6.98.80.01932019-01-15
CVE-2023-4759 6.98.80.01882023-09-12
CVE-2026-275876.89.10.00372026-02-24
CVE-2026-275886.89.10.00372026-02-24
CVE-2026-156176.79.10.00282026-07-23