The product does not properly handle when an input contains Unicode encoding.
Volume of CVEs assigned to CWE-176 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43093HIGH In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicod | Nov 13, 2024 | 7.3 | 62 | YES | NO |
CVE-2025-71316CRITICAL SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load | Jun 4, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-48618MEDIUM A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname | Jun 26, 2026 | 6.5 | 36 | NO | NO |
CVE-2026-45135HIGH Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go mi | Jun 23, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-49401HIGH Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path | Jun 23, 2026 | 8.4 | 32 | NO | NO |
CVE-2024-24691CRITICAL Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalati | Feb 14, 2024 | 9.8 | 32 | NO | NO |
CVE-2026-59890MEDIUM setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude | Jul 8, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-7040HIGH Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters.
The minify functions mishandled some malformed UTF | Apr 27, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-45062HIGH FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.Igno | Jun 10, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-4116HIGH Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication. | Apr 9, 2026 | 7.2 | 26 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.