Cyber Resilience

CWE · MITRE source

CWE-177Improper Handling of URL Encoding (Hex Encoding)

Abstraction: Variant · CVEs in our corpus: 14

The product does not properly handle when all or part of an input has been URL encoded.

Last updated: 21 August 2026 14:15 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 3 mapping(s) from 1 framework(s): CAPEC 3 (mostly)

See the full cumulative-coverage rollup →

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.2.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-410416.99.10.00472026-07-13
CVE-2026-590836.89.10.00372026-07-14
CVE-2022-27780 6.37.50.02472022-06-02
CVE-2026-22031 6.08.40.00462026-01-19
CVE-2026-22037 5.98.40.00332026-01-19
CVE-2026-290455.97.50.00502026-03-04
CVE-2026-153715.68.10.00212026-08-18
CVE-2022-3854 5.26.50.00562023-03-06
CVE-2026-674484.86.50.00152026-08-20
CVE-2018-3718 4.75.30.01322018-06-07
CVE-2026-6414 4.75.90.00412026-04-16
CVE-2024-48866 4.55.30.00432024-12-06
CVE-2025-119902.83.10.00302025-11-15