CWE-1007: Insufficient Visual Distinction of Homoglyphs Presented to User

low-risk

The product displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.

Abstraction: Base

Common Consequences

Integrity Other

Detection Methods

Manual Dynamic Analysis

If utilizing user accounts, attempt to submit a username that contains homoglyphs. Similarly, check to see if links containing homoglyphs can be sent via email, web browsers, or other mechanisms.

Real-World Examples (2)

CVE CVSS EPSS KEV
CVE-2021-4221 4.3 0.2%
CVE-2025-0996 5.4 0.1%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal