CWE-174: Double Decoding of the Same Data
The product decodes the same input twice, which can limit the effectiveness of any protection mechanism that occurs in between the decoding operations.
1 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-75899 — fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding
Recently published
- CVE-2026-75899 — fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding