CWE-176
CVEs classified under CWE-176, newest first.
8 CVEsRSS
CVE-2026-93990High· 7.5Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted
Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following c…
CVE-2026-93751Medium· 6.5uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platfor…
CVE-2026-81869Medium· 5.1PoCOpenTelemetry-Go is the Go implementation of OpenTelemetry
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing…
CVE-2026-59890Medium· 6.1setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
CVE-2026-35346Low· 3.3comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
CVE-2026-35373Low· 3.3ln: rejects non-UTF-8 source filenames in target-directory mode
ln: rejects non-UTF-8 source filenames in target-directory mode
CVE-2026-49401Medium· 5.2Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
CVE-2026-23950High· 8.8node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalizatio…