CWE-173: Improper Handling of Alternate Encoding
The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-10050 — Digest authentication lossy encoding
- CVE-2026-19611 — Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding
- CVE-2026-81638 — Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
Recently published
- CVE-2026-81638 — Non-canonical ULID spellings are accepted and alias to the same record in ash_double_entry
- CVE-2026-19611 — Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding
- CVE-2026-10050 — Digest authentication lossy encoding