CWE-172: Encoding Error
The product does not properly encode or decode the data, resulting in unexpected values.
8 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-27110 — Libmodsecurity3 has possible bypass of encoded HTML entities
- CVE-2026-42926 — NGINX ngx_http_proxy_v2_module vulnerability
- CVE-2026-48784 — Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
- CVE-2024-48909 — SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
Recently published
- CVE-2026-48784 — Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
- CVE-2026-42926 — NGINX ngx_http_proxy_v2_module vulnerability
- CVE-2025-27110 — Libmodsecurity3 has possible bypass of encoded HTML entities
- CVE-2024-48909 — SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not