VYPR

CWE-174

Double Decoding of the Same Data

VariantDraft

Description

The product decodes the same input twice, which can limit the effectiveness of any protection mechanism that occurs in between the decoding operations.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (2)

  • CVE-2026-75899HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.00

    fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different…

  • CVE-2026-92839MedSep 17, 2026
    risk 0.28cvss 4.3epss 0.00

    Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.