The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.
Volume of CVEs assigned to CWE-150 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-62948CRITICAL OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefil | Jul 15, 2026 | 9.6 | 41 | NO | NO |
CVE-2025-55754CRITICAL Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in | Oct 27, 2025 | 9.6 | 41 | NO | NO |
CVE-2026-11362CRITICAL DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags.
DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data | Jun 5, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-11373CRITICAL Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections.
Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd.
Newlines | Jun 22, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-50638CRITICAL Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions such as dogstatsd) allow mutiple met | Jun 10, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-9270CRITICAL DataDog::DogStatsd versions through 0.07 for Perl allow metric injections.
DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted s | Jun 5, 2026 | 9.1 | 34 | NO | NO |
CVE-2026-23829MEDIUM Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression | Jan 19, 2026 | 5.3 | 34 | NO | YES |
CVE-2026-49147HIGH App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes.
When ack prints a filename whose basename contains te | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-50637HIGH Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions) allow mutiple metrics, separated by ne | Jun 10, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-46741HIGH Etsy::StatsD versions through 1.002002 for Perl allow metric injections.
The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untruste | Jun 4, 2026 | 7.5 | 32 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.