2 vulnerabilities classified as CWE-147 (输入终结符转义处理不恰当). AI Chinese analysis included.
CWE-147 represents a critical input validation weakness where software fails to properly neutralize special characters that act as terminators for downstream components. This flaw allows attackers to inject malicious payloads by exploiting protocol-specific delimiters, such as using a period in SMTP to prematurely end a message or inserting null bytes to truncate strings. By bypassing expected input boundaries, adversaries can manipulate command execution, alter data integrity, or trigger unexpected application behaviors. To mitigate this risk, developers must implement rigorous input sanitization and strict validation routines that explicitly filter or escape known terminator characters before processing. Additionally, employing parameterized queries and adhering to the principle of least privilege ensures that even if input is malformed, the downstream component remains protected from interpreting these injected terminators as legitimate control signals, thereby maintaining system stability and security.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-7962 | Eclipse Jakarta Mail 安全漏洞 — Jakarta Mail | 7.5 | - | 2025-07-21 |
| CVE-2024-52505 | matrix-appservice-irc allows IRC Command injection in provisioning API — matrix-appservice-irc | 5.4 | Medium | 2024-11-14 |
Vulnerabilities classified as CWE-147 (输入终结符转义处理不恰当) represent 2 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.