← Back
CWE-173

3 CVEs • Abstraction: Variant

Improper Handling of Alternate Encoding

The product does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.

JSON object

Loading...

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jetbrains
1Youtrack
Jun 17, 2026
Dec 4, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
1Executablebooks
1Markdown It Py
Jun 17, 2026
Feb 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.
1Executablebooks
1Markdown It Py
Jun 17, 2026
Feb 22, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Denial of service could be caused to the command line interface of markdown-it-py, before v2.2.0, if an attacker was allowed to use invalid UTF-8 characters as input.