CWE-176

CWE-176 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-176, highest CVSS first.

  1. HIGH 7.5CVE-2026-93990public PoC

    Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 encoded XML with lone high surrogates that consume following code units, hiding marku…

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-19954public PoC

    Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing …

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-86105

    An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different …

    AI risk analysis on Exploit-DB.ai →