CWE-174— Double Decoding of the Same Data
The product decodes the same input twice, which can limit the effectiveness of any protection mechanism that occurs in between the decoding operations.— MITRE CWE catalog
2 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-174page 1 of 1
- CVE-2026-75899HIGHCVSS 7.5EG 7.52026-08-24
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested perce…
- CVE-2026-92839MEDIUMCVSS 4.3EG 4.32026-09-17
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.
Map vulnerabilities like CWE-174 to your infrastructure
EchelonGraph correlates every CVE — across CWE-174 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →