VulnSea

CWE-176

CVEs classified under CWE-176, newest first.

8 CVEsRSS

CVE-2026-93990High· 7.5
3d ago

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following c…

Twilightlibexpat · libexpatEPSS 0.35%via NVD
CVE-2026-93751Medium· 6.5
4d ago

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platfor…

Sunlitgarycourt · uri-jsEPSS 0.23%via NVD
CVE-2026-81869Medium· 5.1PoC
6d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing…

Twilightopen-telemetry · opentelemetry-goEPSS 0.13%via NVD
CVE-2026-59890Medium· 6.1
2mo ago

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

Sunlitsetuptools · setuptoolsEPSS 0.40%via OSV
CVE-2026-35346Low· 3.3
2mo ago

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

Sunlituu_comm · uu_commEPSS 0.18%via GHSA
CVE-2026-35373Low· 3.3
2mo ago

ln: rejects non-UTF-8 source filenames in target-directory mode

ln: rejects non-UTF-8 source filenames in target-directory mode

Sunlituu_ln · uu_lnEPSS 0.12%via GHSA
CVE-2026-49401Medium· 5.2
3mo ago

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Sunlitdeno · denoEPSS 0.20%via GHSA
CVE-2026-23950High· 8.8
8mo ago

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalizatio…

Twilightisaacs · tarEPSS 0.26%via NVD
CWE-176 vulnerabilities (CVEs) · VulnSea