# CWE-35: Path Traversal: '.../...//'

**KEV-linked**

> As of 2026-10-05, CWE-35 (Path Traversal: '.../...//') underlies 3 CVEs tracked by Threadlinqs, 1 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 14 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-35?

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

CWE-35 is a variant-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Not Language-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/35.html) (CWE-35 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality, Integrity** — Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism. Not properly neutralizing '.../...//' (doubled triple dot slash) allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

_Source: MITRE CWE, common consequences._

## How CWE-35 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-35, published between 2025-08-08 and 2026-06-09. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild. By CVSS v3 severity the set splits into 1 critical, 1 high, 1 medium. The highest EPSS score in the set is 7.0% (CVE-2025-8088), the modelled probability of exploitation in the next 30 days. 14 tracked threats reference CWE-35 directly or through a CVE it covers; the most recent is “GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)” (2026-09-11). Affected products concentrate in Microsoft (2), Dtsearch (1), Rarlab (1), among 4 vendors in total.

## Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-35, CISA KEV first, then by CVSS score.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088) — CISA KEV · CVSS 8.8 high · EPSS 7.0% · published 2025-08-08
- [CVE-2026-40128](https://intel.threadlinqs.com/cve/CVE-2026-40128) — CVSS 9 critical · EPSS 0.4% · published 2026-06-09
- [CVE-2026-26124](https://intel.threadlinqs.com/cve/CVE-2026-26124) — CVSS 6.7 medium · EPSS 0.1% · published 2026-03-05

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 2 CVEs
- **Dtsearch** — 1 CVE
- **Rarlab** — 1 CVE
- [SAP_SE](https://intel.threadlinqs.com/vendors/sap-se) — 1 CVE

## Threat activity

14 tracked threats cite CWE-35:

- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2442) — CRITICAL · 2026-09-11
- [CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-1438) — CRITICAL · 2026-07-17
- [SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)](https://intel.threadlinqs.com/threat/TL-2026-1302) — CRITICAL · 2026-07-14
- [SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security Notes](https://intel.threadlinqs.com/threat/TL-2026-1303) — CRITICAL · 2026-07-14
- [Gamaredon (Primitive Bear / Shuckworm) APT Profile: Russia-Aligned Espionage Against Ukraine and NATO, Now Exploiting CVE-2025-8088 (WinRAR)](https://intel.threadlinqs.com/threat/TL-2026-1210) — HIGH · 2026-07-11
- [Gamaredon Expands Ukraine Attacks with PteroSetup Revival and Cloud Service Abuse, Exploiting WinRAR Flaw CVE-2025-8088](https://intel.threadlinqs.com/threat/TL-2026-1216) — HIGH · 2026-06-29
- [Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088](https://intel.threadlinqs.com/threat/TL-2026-0966) — HIGH · 2026-06-28
- [Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)](https://intel.threadlinqs.com/threat/TL-2026-0968) — HIGH · 2026-06-28
- [Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations](https://intel.threadlinqs.com/threat/TL-2026-0723) — HIGH · 2026-06-09
- [Microsoft Edge CVE-2026-45495 — Feedback-Log Path-Validation Remote Code Execution](https://intel.threadlinqs.com/threat/TL-2026-0703) — HIGH · 2026-06-07
- [Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access](https://intel.threadlinqs.com/threat/TL-2026-0653) — HIGH · 2026-06-02
- [Microsoft Office RCE via Preview Pane (CVE-2026-26110, CVE-2026-26113) — March 2026 Patch Tuesday](https://intel.threadlinqs.com/threat/TL-2026-0211) — CRITICAL · 2026-03-11
- [UAC-0252 SHADOWSNIFF & SALATSTEALER — Credential Theft Campaign Impersonating Ukrainian Government via GitHub-Hosted Payloads and XSS Delivery](https://intel.threadlinqs.com/threat/TL-2026-0171) — HIGH · 2026-03-02
- [RomCom & Paper Werewolf Exploiting WinRAR CVE-2025-8088 Zero-Day via ADS Path Traversal](https://intel.threadlinqs.com/threat/TL-2026-0090) — CRITICAL · 2026-02-04

## Mitigations

- **Implementation / Input Validation**: Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected…
- **Implementation / Input Validation**: Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous inputs after they have been checked.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-23 Relative Path Traversal](https://intel.threadlinqs.com/cwe/CWE-23)

Canonical: https://intel.threadlinqs.com/cwe/CWE-35
Source definition: https://cwe.mitre.org/data/definitions/35.html
Detection rules and IOCs for threats exploiting CWE-35 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
