Cyber Resilience

CWE · MITRE source

CWE-35Path Traversal: '.../...//'

Abstraction: Variant · CVEs in our corpus: 179

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Last updated: 20 August 2026 13:14 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • AC-3 Access Enforcement
  • AC-4 Information Flow Enforcement
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-27130 9.39.10.65912020-11-17
CVE-2025-8088 KEV 9.28.80.94552025-08-08
CVE-2023-32714 8.08.10.42822023-06-01
CVE-2018-3744 7.79.80.02272018-05-29
CVE-2025-24786 7.710.00.02672025-02-06
CVE-2024-39171 7.59.80.01212024-07-09
CVE-2025-41723 7.59.80.01262025-10-22
CVE-2025-42937 7.49.80.00692025-10-14
CVE-2025-30515 7.39.80.00532025-06-09
CVE-2026-6074 7.39.80.00552026-04-23
CVE-2025-59793 7.19.90.01032026-02-17
CVE-2024-2863 7.05.30.64002024-03-25
CVE-2026-45661 7.09.90.00662026-05-29
CVE-2026-591157.09.90.00632026-08-07
CVE-2023-46690 6.98.80.01852023-11-30
CVE-2024-36991 6.97.50.13012024-07-01
CVE-2020-26073 6.87.50.12062024-11-18
CVE-2024-56045 6.89.30.00682024-12-31
CVE-2026-7302 6.89.10.00392026-05-18
CVE-2024-47169 6.78.80.00782024-09-26
CVE-2025-417366.78.80.00722025-11-18
CVE-2026-20034 6.78.80.00712026-05-06
CVE-2026-45495 6.78.80.00992026-05-18
CVE-2026-527036.79.60.00442026-06-15
CVE-2023-39916 6.69.30.00552023-09-13