CWE-158: Improper Neutralization of Null Byte or NUL Character
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.
26 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-47812 — In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
- CVE-2025-55113 — BMC Control-M/Agent unescaped NULL byte in access control list checks
- CVE-2025-66263 — Unauthenticated Arbitrary File Read via Null Byte Injection
- CVE-2026-33191 — free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
- CVE-2025-9648 — Denial of Service in CivetWeb
- CVE-2024-10921 — Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server
- CVE-2026-76354 — Path Traversal through Search Head Clustering in Splunk Enterprise
- CVE-2026-70603 — Electron: shell.openPath path validation bypass via embedded null byte
- CVE-2026-41256 — jq: Embedded NUL truncates top-level jq programs loaded with -f
- CVE-2026-28540 — Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec
- CVE-2026-47778 — Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
- CVE-2026-43895 — jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
- CVE-2024-9026 — PHP-FPM logs from children may be altered
- CVE-2026-43861 — mutt before 2.3.2 does not check for '\0' in url_pct_decode.
- CVE-2026-43859 — mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
- CVE-2026-4359 — Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer
Recently published
- CVE-2026-76354 — Path Traversal through Search Head Clustering in Splunk Enterprise
- CVE-2026-70603 — Electron: shell.openPath path validation bypass via embedded null byte
- CVE-2026-47778 — Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)
- CVE-2026-43895 — jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
- CVE-2026-41256 — jq: Embedded NUL truncates top-level jq programs loaded with -f
- CVE-2026-43861 — mutt before 2.3.2 does not check for '\0' in url_pct_decode.
- CVE-2026-43859 — mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
- CVE-2026-33191 — free5GC UDM vulnerable to null byte injection in URL path parameters causing 500 Internal Server Error
- CVE-2026-4359 — Heap-buffer-over-read in _mongoc_http_send via strstr on non-null-terminated buffer
- CVE-2026-28540 — Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec
- CVE-2025-66263 — Unauthenticated Arbitrary File Read via Null Byte Injection
- CVE-2025-9648 — Denial of Service in CivetWeb
- CVE-2025-55113 — BMC Control-M/Agent unescaped NULL byte in access control list checks
- CVE-2025-47812 — In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
- CVE-2024-10921 — Improper neutralization of null bytes may lead to buffer over-reads in MongoDB Server
- CVE-2024-9026 — PHP-FPM logs from children may be altered