CWE-174
CVEs classified under CWE-174, newest first.
2 CVEsRSS
CVE-2026-92839Medium· 4.3Canva Desktop before v1.125.0 performed double decoding in the deeplink handler
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
▾ SunlitCanva · CanvaEPSS 0.21%via NVD
CVE-2026-75899High· 7.5fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding (CVE-2026-75899)
A flaw was found in fast-uri, a URI parser for Node.js. The component incorrectly decodes percent escapes in a hostname twice during URI parsing and authority recomposition. This double decoding can allow a remote attacker to manipulate a …
▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF