CWE-176: Improper Handling of Unicode Encoding
The product does not properly handle when an input contains Unicode encoding.
28 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-24691 — Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows - Improper Input Validation
- CVE-2006-10002 — XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes
- CVE-2025-71316 — SQLite sqldiff remote code execution via argument injection
- CVE-2026-23950 — node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
- CVE-2026-45135 — Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
- CVE-2026-45062 — FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
- CVE-2026-48618 — A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth
- CVE-2026-25480 — FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
- CVE-2024-47611 — XZ Utils on Microsoft Windows platform are vulnerable to argument injection
- CVE-2026-7040 — Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters
- CVE-2026-49401 — Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
- CVE-2026-4116 — Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t
- CVE-2026-4114 — Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin
- CVE-2026-20202 — Improper Input Validation during User Account Creation in Splunk Enterprise
- CVE-2025-59547 — DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation
- CVE-2026-59890 — setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
- CVE-2026-14978 — Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
- CVE-2026-44288 — protobufjs: Overlong UTF-8 decoding
- CVE-2026-35375 — uutils coreutils split Local Data Integrity Issue via Lossy Filename Encoding
- CVE-2026-35373 — uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames
Recently published
- CVE-2026-14978 — Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
- CVE-2026-59890 — setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
- CVE-2026-48618 — A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth
- CVE-2026-45135 — Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
- CVE-2026-49401 — Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
- CVE-2026-45062 — FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
- CVE-2025-71316 — SQLite sqldiff remote code execution via argument injection
- CVE-2026-44288 — protobufjs: Overlong UTF-8 decoding
- CVE-2026-7040 — Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have heap overflow when processing some malformed UTF-8 characters
- CVE-2026-35375 — uutils coreutils split Local Data Integrity Issue via Lossy Filename Encoding
- CVE-2026-35373 — uutils coreutils ln Local Denial of Service via Improper Handling of Non-UTF-8 Filenames
- CVE-2026-35346 — uutils coreutils comm Silent Data Corruption via Lossy UTF-8 Normalization
- CVE-2026-20202 — Improper Input Validation during User Account Creation in Splunk Enterprise
- CVE-2026-4116 — Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t
- CVE-2026-4114 — Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin
- CVE-2006-10002 — XML::Parser versions through 2.45 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes
- CVE-2026-25480 — FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
- CVE-2026-23950 — node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS
- CVE-2025-59547 — DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation
- CVE-2024-47611 — XZ Utils on Microsoft Windows platform are vulnerable to argument injection