CWE · MITRE source
CWE-177Improper Handling of URL Encoding (Hex Encoding)
The product does not properly handle when all or part of an input has been URL encoded.
Last updated: 21 August 2026 14:15 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 3 mapping(s) from 1 framework(s): CAPEC 3 (mostly)
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
Detect
Catch it (CSF Detect / Respond)
—
Harden
Shrink the surface (DISA STIG)
—
Validate
Prove the fix (OWASP ASVS)
V1.2.2
NIST 800-53 r5 controls that address this weakness (0)AI-assisted
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2026-41041 | 6.9 | 9.1 | 0.0047 | 2026-07-13 |
CVE-2026-59083 | 6.8 | 9.1 | 0.0037 | 2026-07-14 |
CVE-2022-27780 UPD | 6.3 | 7.5 | 0.0247 | 2022-06-02 |
CVE-2026-22031 UPD | 6.0 | 8.4 | 0.0046 | 2026-01-19 |
CVE-2026-22037 UPD | 5.9 | 8.4 | 0.0033 | 2026-01-19 |
CVE-2026-29045 | 5.9 | 7.5 | 0.0050 | 2026-03-04 |
CVE-2026-15371 | 5.6 | 8.1 | 0.0021 | 2026-08-18 |
CVE-2022-3854 UPD | 5.2 | 6.5 | 0.0056 | 2023-03-06 |
CVE-2026-67448 | 4.8 | 6.5 | 0.0015 | 2026-08-20 |
CVE-2018-3718 UPD | 4.7 | 5.3 | 0.0132 | 2018-06-07 |
CVE-2026-6414 UPD | 4.7 | 5.9 | 0.0041 | 2026-04-16 |
CVE-2024-48866 UPD | 4.5 | 5.3 | 0.0043 | 2024-12-06 |
CVE-2025-11990 | 2.8 | 3.1 | 0.0030 | 2025-11-15 |