CWE-176— Improper Handling of Unicode Encoding
The product does not properly handle when an input contains Unicode encoding.— MITRE CWE catalog
37 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-176page 1 of 1
- CVE-2024-43093CRITICALCVSS 7.3EG 9.0⚠ KEV2024-11-13
In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of pri…
- CVE-2025-71316CRITICALCVSS 9.8EG 9.82026-06-04
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument strin…
- CVE-2006-10002CRITICALCVSS 7.5EG 9.82026-03-19
XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer …
- CVE-2024-24691CRITICALCVSS 9.6EG 9.62024-02-14
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.
- CVE-2023-39213CRITICALCVSS 9.6EG 9.62023-08-08
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.
- CVE-2024-8067CRITICALCVSS 5.8EG 9.42024-09-25
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.
- CVE-2026-49401HIGHCVSS 8.4EG 8.42026-06-16
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path against the path supplied to --deny-read, --deny-write, --d…
- CVE-2026-45135HIGHCVSS 8.1EG 8.12026-05-18
Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when …
- CVE-2026-45062HIGHCVSS 8.1EG 8.12026-05-15
FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two…
- CVE-2026-48618HIGHCVSS 6.5EG 7.72026-06-26
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality i…
- CVE-2026-93990HIGHCVSS 7.5EG 7.52026-09-19
Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that con…
- CVE-2026-7040HIGHCVSS 7.5EG 7.52026-04-27
Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters. The minify functions mishandled some malformed UTF-8 characters, leading to heap corruption. Note that the m…
- CVE-2026-4116HIGHCVSS 7.2EG 7.22026-04-09
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
- CVE-2026-86105HIGHCVSS 7.1EG 7.12026-09-29
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted req…
- CVE-2026-20202MEDIUMCVSS 6.6EG 6.62026-04-15
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, a user who holds a role that contains th…
- CVE-2026-4114MEDIUMCVSS 6.6EG 6.62026-04-09
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
- CVE-2026-93751MEDIUMCVSS 6.5EG 6.52026-09-18
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform …
- CVE-2026-25480MEDIUMCVSS 6.5EG 6.52026-02-09
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileSt…
- CVE-2024-47611MEDIUMCVSS 6.3EG 6.32024-10-02
XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerabili…
- CVE-2026-59890MEDIUMCVSS 6.1EG 6.12026-07-08
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compi…
- CVE-2026-23950MEDIUMCVSS 5.9EG 5.92026-01-20
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-…
- CVE-2026-14978MEDIUMCVSS 5.5EG 5.52026-08-19
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matc…
- CVE-2026-19954MEDIUMCVSS 5.4EG 5.42026-10-05
Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Ap…
- CVE-2025-55129MEDIUMCVSS 5.4EG 5.42025-12-02
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impe…
- CVE-2026-105241MEDIUMCVSS 5.3EG 5.32026-10-06
Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the b…
- CVE-2026-44288MEDIUMCVSS 5.3EG 5.32026-05-13
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters inste…
- CVE-2025-59547MEDIUMCVSS 5.3EG 5.32025-09-23
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network e…
- CVE-2023-52081MEDIUMCVSS 5.3EG 5.32023-12-28
ffcss is a CLI interface to apply and configure Firefox CSS themes. Prior to 0.2.0, the function `lookupPreprocess()` is meant to apply some transformations to a string by disabling characters in the regex `[-_ .]`. However, due to the use…
- CVE-2023-41889MEDIUMCVSS 5.3EG 5.32023-09-15
SHIRASAGI is a Content Management System. Prior to version 1.18.0, SHIRASAGI is vulnerable to a Post-Unicode normalization issue. This happens when a logical validation or a security check is performed before a Unicode normalization. The U…
- CVE-2020-8929MEDIUMCVSS 5.3EG 5.32020-10-19
A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID part of a ciphertext, which result in the creation of a second ciphertext that can decrypt to the sam…
- CVE-2026-81869MEDIUMCVSS 5.1EG 5.12026-09-16
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing t…
- CVE-2023-31169MEDIUMCVSS 4.8EG 4.82023-08-31
An Improper Handling of Unicode Encoding vulnerability in the Schweitzer Engineering Laboratories SEL-5030 acSELerator QuickSet Software could allow an attacker to embed instructions that could be executed by an authorized device operator…
- CVE-2026-35375LOWCVSS 3.3EG 3.32026-04-22
A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-UTF-8 prefix or suffix inputs. The implementation utilizes to_string_lossy() when constructing chunk filenames, which a…
- CVE-2026-35373LOWCVSS 3.3EG 3.32026-04-22
A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filename bytes when using target-directory forms (e.g., ln SOURCE... DIRECTORY). While GNU ln treats filenames as raw bytes …
- CVE-2026-35346LOWCVSS 3.3EG 3.32026-04-22
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 byte sequences with the Unicode replaceme…
- CVE-2022-29812LOWCVSS 2.3EG 2.32022-04-28
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient
- CVE-2017-20190UnratedEG not assessed2024-03-27
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether th…
Map vulnerabilities like CWE-176 to your infrastructure
EchelonGraph correlates every CVE — across CWE-176 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →