CWE-116 - Improper Encoding or Escaping of Output is a cwe tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed June 6, 2026; most recent activity June 6, 2026.
CVE-2026-16117 was published on July 18, 2026, detailing a critical vulnerability in @fastify/http-proxy versions up to 11.5.0. The flaw allows attackers to bypass request prefix rewrites when the prefix is URL-encoded,…
On March 10, 2026, three critical vulnerabilities were published affecting Substance3D software. CVE-2026-21365 and CVE-2026-27219 both impact Substance3D - Painter versions 11.1.2 and earlier, exposing users to…