inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.","DatePublished":"2026-04-22T07:00:00.000Z","DomainCount":446},{"CVEId":"CVE-2026-3108","Title":"Terminal Escape Injection in mmctl Report Posts Command","Description":"Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences that enable screen manipulation, fake prompts, and clipboard hijacking.. Mattermost Advisory ID: MMSA-2026-00599","DatePublished":"2026-03-26T07:00:00.000Z","DomainCount":78},{"CVEId":"CVE-2025-65082","Title":"Apache HTTP Server: CGI environment variable override","Description":"Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.\n\nThis issue affects Apache HTTP Server from 2.4.0 through 2.4.65.\n\nUsers are recommended to upgrade to version 2.4.66 which fixes the issue.","DatePublished":"2025-12-05T08:00:00.000Z","DomainCount":1297929},{"CVEId":"CVE-2025-55754","Title":"Apache Tomcat: console manipulation via escape sequences in log messages","Description":"Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat.\n\nTomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.\n\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.\nUsers are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.","DatePublished":"2025-10-27T07:00:00.000Z","DomainCount":2303},{"CVEId":"CVE-2025-55193","Title":"Active Record logging vulnerable to ANSI escape injection","Description":"Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.","DatePublished":"2025-08-13T07:00:00.000Z","DomainCount":1},{"CVEId":"CVE-2024-47252","Title":"Apache HTTP Server: mod_ssl error log variable escaping","Description":"Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations.\n\nIn a logging configuration where CustomLog is used with \"%{varname}x\" or \"%{varname}c\" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.","DatePublished":"2025-07-10T07:00:00.000Z","DomainCount":1248307}],"DistributionByPopularity":{"Top10KUsage":133,"Top100KUsage":2164,"Top1MUsage":26733,"Top10MUsage":202179,"TotalCount":1300448,"TotalDomainCount":57867524},"TLDs":[{"TLD":"com","DomainCount":471807},{"TLD":"de","DomainCount":88213},{"TLD":"org","DomainCount":63614},{"TLD":"net","DomainCount":52643},{"TLD":"nl","DomainCount":40191},{"TLD":"ru","DomainCount":39959},{"TLD":"it","DomainCount":39068},{"TLD":"cz","DomainCount":33092},{"TLD":"fr","DomainCount":26408},{"TLD":"pl","DomainCount":24160}],"DomainCount":1300448,"success_msg":[],"error_msg":[],"error":[]}}}
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.