Skip to main content

Threats Tagged 'cwe-176'

View all threats tagged with 'cwe-176'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-176

Threats Tagged 'cwe-176'

Click on any threat for detailed analysis and mitigation recommendations

Improper Handling of Unicode Encoding vulnerability in the SmtpPickupDirAppender of Apache log4net. Content that the mail file writer cannot encode, such as an unpaired UTF-16 surrogate, made the write throw. Every buffered event in the batch was discarded, not only the one carrying the content, and a truncated mail could be left in the pickup directory. A party whose data reaches a log message could suppress the records of other events. Only applications that use SmtpPickupDirAppender are affected. This issue affects Apache log4net: from 1.2.9 before 3.5.0. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Join the discussion

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each non-ASCII label directly using Net::IDN::Punycode and prepends xn--. Apart from lowercasing ASCII and Cyrillic letters, it skips the IDNA mapping and normalization steps, so a label with other uppercase letters, or not in NFC, encodes to a different A-label than its IDNA form. For example, a label of U+00C9 followed by "cole" encodes to "xn--cole-pka" rather than "xn--cole-9oa". The Net::Whois::Raw library modules are not affected.

Join the discussion
0

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.

Join the discussion

### Summary The OpenTelemetry Go SDK trace package can fail to enforce `AttributeValueLengthLimit` for string attributes containing the valid Unicode replacement character U+FFFD. An oversized attacker-controlled attribute value that includes U+FFFD is returned untruncated, bypassing the configured memory/DoS protection and allowing increased per-span memory usage. The finding is low severity because it requires a deployment with attribute value length limits enabled and attacker-controlled data being recorded into span attributes. Introduced in commit 49a6536 ### Details String and string-slice span attributes are truncated through `safeTruncate` when `AttributeValueLengthLimit` is non-negative. The finding evidence identifies this enforcement path in `sdk/trace/span.go:303-331`, with string attributes passed to `safeTruncate` at `sdk/trace/span.go:309-310` and string-slice entries passed to `safeTruncate` in the loop beginning at `sdk/trace/span.go:312`. `safeTruncate` first calls `safeTruncateValidUTF8`; if that returns `ok=false`, it calls `strings.ToValidUTF8(input, "")` and retries. The relevant code is identified in `sdk/trace/span.go:337-355`. `safeTruncateValidUTF8` treats any `utf8.RuneError` from `utf8.DecodeRuneInString` as invalid UTF-8 and immediately returns the original input with `ok=false`. However, Go also returns `utf8.RuneError` for a valid encoded U+FFFD rune. The validation artifact confirms this behavior with output `r=U+FFFD size=3 runeError=true`. For an input such as `"AAAA" + U+FFFD + strings.Repeat("B", 20)` and a limit of 5, the first truncation attempt sees U+FFFD as `utf8.RuneError` and returns the full input with `ok=false`. `strings.ToValidUTF8` does not remove the valid U+FFFD rune, so the second attempt returns the same full input. As a result, the span attribute value remains 27 bytes long even though the configured limit is 5. ### PoC [validation-artifact.zip](https://github.com/user-attachments/files/27494267/validation-artifact.zip) The validation artifact contains a package-level Go test at `validation-artifact.tar:safe_truncate_bypass/safe_truncate_poc_test.go` and supporting output at `validation-artifact.tar:safe_truncate_bypass/runecheck_output.txt`. Reproduction configuration: - Repository: `pellared/opentelemetry-go` - Commit: `49a6536` from September 12, 2022 - Package/module path: `sdk/trace` under the `sdk` module - Attribute value length limit used by the PoC: `limit := 5` - Dependencies must be available through the network or a local module cache/vendor directory. Commands: ```sh cd /path/to/opentelemetry-go git checkout 49a6536 tar -xOf /path/to/validation-artifact.tar safe_truncate_bypass/safe_truncate_poc_test.go > sdk/trace/safe_truncate_poc_test.go cd sdk go test ./trace -run TestSafeTruncateBypass -count=1 -v ``` Expected vulnerable output includes a failing test showing that the returned value exceeds the configured limit: ```text === RUN TestSafeTruncateBypass safe_truncate_poc_test.go:14: input_len=27 got_len=27 input="AAAA�BBBBBBBBBBBBBBBBBBBB" got="AAAA�BBBBBBBBBBBBBBBBBBBB" safe_truncate_poc_test.go:16: bypass: got_len 27 > limit 5 --- FAIL: TestSafeTruncateBypass ``` The artifact also records the standalone UTF-8 behavior needed for the bypass: ```sh tar -xOf /path/to/validation-artifact.tar safe_truncate_bypass/runecheck_output.txt ``` Expected output: ```text r=U+FFFD size=3 runeError=true ``` ### Impact This is a Unicode handling and resource-limit bypass that weakens span attribute memory controls. Applications that enable `AttributeValueLengthLimit` to bound memory usage can still store oversized attacker-controlled attribute values if those values contain U+FFFD. The practical impact is increased memory use and reduced denial-of-service protection in the instrumented process; the finding does not show confidentiality or integrity impact.

Join the discussion

HashiCorp go-slug versions 0.4.0 through 0.18.2 contain a vulnerability where improper handling of Unicode normalization during path matching can allow a local attacker to bypass .terraformignore exclusions. This may result in sensitive files being included in Terraform slug uploads.

Join the discussion

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

Join the discussion

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Join the discussion

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Join the discussion

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.

Join the discussion

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem and execution restrictions by comparing the requested path against the path supplied to --deny-read, --deny-write, --deny-run, or --deny-ffi. On macOS, that comparison was done at the raw-byte level while the APFS filesystem treats different Unicode spellings of the same name as the same file. That means a program could reach a denied path by spelling it differently than the deny rule. This vulnerability is fixed in 2.7.14.

Join the discussion

Showing 1 to 10 of 22 results

Filters:Tag: cwe-176
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses