CWE-158: Improper Neutralization of Null Byte or NUL Character

low-risk

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.

Abstraction: Variant

Common Consequences

Integrity Unexpected State

Real-World Examples (10)

CVE CVSS EPSS KEV
CVE-2025-47812 10.0 92.5% Y
CVE-2022-20812 9.0 1.1%
CVE-2024-9026 3.3 0.9%
CVE-2024-10921 6.8 0.5%
CVE-2020-7928 6.5 0.5%
CVE-2022-20813 9.0 0.4%
CVE-2020-14500 10.0 0.3%
CVE-2026-33191 8.6 0.2%
CVE-2025-1936 7.3 0.2%
CVE-2025-14388 9.8 0.1%
3
/ 100
low-risk
Active Threat 2/50 · Minimal
Exploit Availability 1/50 · Minimal