CWE-173Variant

Improper Handling of Alternate Encoding

Draft in the CWE catalog · 5 CVEs mapped

5
CVEs mapped
3.5
Median CVSS
What it is

The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.

Recent examples
7.4cvss
CVE-2026-19611

CVE-2026-19611 - HIGH Severity Vulnerability

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

HIGHno explanation yet
0%
epss
9.1cvss
CVE-2026-10050

CVE-2026-10050 - CRITICAL Severity Vulnerability

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

CRITICALno explanation yet
0%
epss
3.5cvss
CVE-2024-54158

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-173
Abstraction
Variant
Structure
Simple
Status
Draft