CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences

Parent: CWE-138 - Improper Neutralization of Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

68 vulnerabilities with CWE-150
CVE-2026-39879 HIGH
SQL injection in syslog-ng SQL destionation driver
CVSS 7.1
CVE-2026-62948 CRITICAL
OpenWrt < 25.12.5 odhcpd/LuCI - Stored Cross-Site Scripting
CVSS 9.6
CVE-2026-49147 HIGH
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
CVSS 7.5
CVE-2026-11373 CRITICAL
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
CVSS 9.1
CVE-2026-54057 HIGH
Kitty vulnerable to command injection via unsanitized OSC 21 query reply
CVSS 7.8
CVE-2026-50639 MEDIUM
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections
CVSS 6.5
CVE-2026-50638 CRITICAL
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections
CVSS 9.1
CVE-2026-50637 HIGH
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections
CVSS 8.2
CVE-2026-9270 CRITICAL
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
CVSS 9.1
CVE-2026-11362 CRITICAL
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
CVSS 9.8
CVE-2026-46741 HIGH
Etsy::StatsD versions through 1.002002 for Perl allow metric injections
CVSS 7.5
CVE-2026-46739 MEDIUM
Net::Statsd versions before 0.13 for Perl allow metric injections
CVSS 5.3
CVE-2026-8722 MEDIUM
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections
CVSS 6.5
CVE-2026-46740 MEDIUM
Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections
CVSS 5.3
CVE-2026-47090 MEDIUM
Claude HUD 0.0.12 Terminal Injection via OSC 8 Hyperlinks
CVSS 4.6
CVE-2026-8788 HIGH
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections
CVSS 7.3
CVE-2026-46720 HIGH
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections
CVSS 8.2
CVE-2026-46719 MEDIUM
Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections
CVSS 6.5
CVE-2026-45038 HIGH
Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
CVSS 7.8
CVE-2026-45803 LOW
gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
CVSS 3.5
CVE-2026-41526 MEDIUM
KDE KCoreAddons <6.25 - Command Injection
CVSS 6.5
CVE-2026-6019 MEDIUM
BaseCookie.js_output() does not neutralize embedded characters
CVSS 6.1
CVE-2026-40505 LOW
MuPDF mutool ANSI Injection via Metadata
CVSS 3.3
CVE-2026-26149 CRITICAL
Microsoft Power Apps Security Feature Bypass
CVSS 9.0
CVE-2026-35651 MEDIUM
OpenClaw 2026.2.13 < 2026.3.25 - ANSI Escape Sequence Injection in Approval Prompt
CVSS 4.3
Details
Vulnerabilities 68