CVEbaza.plCWE DictionaryCWE-173
Common Weakness Enumeration

CWE-173

Improper Handling of Alternate Encoding

Category: VariantCVE: 7
Description

The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.

CVE vulnerabilities with CWE-173 (7)
8.7
CVSS
HIGH
CVE-2026-10050

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If the password contains characters that cannot be represented in ISO-8859-1, they are silently replaced by `?`. This happens with passwords that contain Chinese, Cyrillic or Greek characters, for example: `αβ123` converts to `??123`. An attacker can send a request with a digest `Authorization` header crafted with a password made of only `?` characters; the server would match any password of the same length that contains non-ISO-8859-1 characters. Recent HTTP Digest [RFC-7616](https://datatracker.ietf.org/doc/html/rfc7616) supports a `charset` parameters that defaults to UTF-8 that allows for correct encoding/decoding of passwords.

pub. 2026-08-04
7.4
CVSS
HIGH
CVE-2026-19611

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.

pub. 2026-08-20
3.5
CVSS
LOW
CVE-2024-54158

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

pub. 2024-12-04
3.3
CVSS
LOW
CVE-2023-26303

Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.

pub. 2023-02-23
3.3
CVSS
LOW
CVE-2023-26302

Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.

pub. 2023-02-22
Information
ID: CWE-173
Type: Variant
Vulnerabilities: 7
MITRE CWE ↗
← CWE Dictionary