CWE-626: Poison Null Byte
The product does not properly handle null bytes or NUL characters when passing data between different representations or components.
7 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-42579 — Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
- CVE-2026-62380 — Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection
- CVE-2026-42040 — Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- CVE-2026-76816 — Netty: MQTT Topic Name and Client ID Validation Bypass
Recently published
- CVE-2026-76816 — Netty: MQTT Topic Name and Client ID Validation Bypass
- CVE-2026-62380 — Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection
- CVE-2026-42579 — Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
- CVE-2026-42040 — Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams