CWE-116: Improper Encoding or Escaping of Output

ClassDraftExploit Likelihood: High

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

View on MITRE
Back to CWE Lookup

Extended Description

Improper encoding or escaping can allow attackers to change the commands that are sent to another component, inserting malicious commands instead. Most products follow a certain protocol that uses structured messages for communication between components, such as queries or commands. These structured messages can contain raw data interspersed with metadata or control information. For example, "GET /index.html HTTP/1.1" is a structured message containing a command ("GET") with a single argument ("/index.html") and metadata about which protocol version is being used ("HTTP/1.1"). If an application uses attacker-supplied inputs to construct a structured message without properly encoding or escaping, then the attacker could insert special characters that will cause the data to be interpreted as control information or metadata. Consequently, the component that receives the output will perform the wrong operations, or otherwise interpret the data incorrectly.

Technical Details

Structure
Simple

Applicable To

Languages
Not Language-Specific
Platforms

Source-backed guidance

Additional facts reviewed against primary or authoritative security sources.

Verify controls for CWE-116 with SSDF evidence

Use NIST SSDF verification and vulnerability-response practices to detect CWE-116, Improper Encoding or Escaping of Output, throughout the product lifecycle. Derive review questions, static or dynamic checks, and negative tests from the CWE's causal behavior; define the components and lifecycle stages each check covers; and retain findings with enough evidence to distinguish the root cause from symptoms and impacts. Track escapes and false negatives, then improve the verification plan after every confirmed occurrence.

NIST SP 800-218 Secure Software Development FrameworkNational Institute of Standards and Technology

Apply Libraries or Frameworks controls for Improper Encoding or Escaping of Output

MITRE associates mitigation with Architecture and Design, Implementation, and Requirements; the listed strategies include Libraries or Frameworks, and Parameterization; documented detection approaches include Automated Static Analysis, and Automated Dynamic Analysis. Use these source-defined anchors to turn CWE-116 into implementation, review, and verification checks for the affected component.

CWE-116: Improper Encoding or Escaping of OutputMITRE CWE

Triage CWE-116 against known exploitation evidence

Use CISA's Known Exploited Vulnerabilities catalog to test whether a vulnerability mapped to CWE-116, Improper Encoding or Escaping of Output, has evidence of exploitation in the wild. Confirm the CVE-to-CWE root-cause mapping independently before attaching the example, then capture the affected product, required action, and remediation deadline. A missing KEV match is not evidence that the weakness is unexploited, and a KEV entry must not be generalized to every occurrence of this CWE.

Known Exploited Vulnerabilities CatalogCybersecurity and Infrastructure Security Agency

Apply precise root-cause mapping to CWE-116

Apply MITRE's full root-cause mapping guidance when using CWE-116, Improper Encoding or Escaping of Output. Separate weakness language from attacker prerequisites and technical impact, check the entry's abstraction and vulnerability-mapping notes, and prefer the most specific Base or Variant supported by the evidence. Record the rejected alternatives and require an independent review before the mapping is used for remediation trends or program metrics.

CVE to CWE Root Cause Mapping GuidanceMITRE CWE

Validate CWE-116 with root-cause mapping checks

Apply MITRE's root-cause mapping quick tips to CWE-116, Improper Encoding or Escaping of Output. Confirm the finding describes the causal weakness rather than an impact or attack pattern, compare the abstraction and mapping notes with plausible alternatives, and have a second reviewer challenge the selection. Preserve the evidence and reasoning so recurring defects can be measured against one consistent identifier.

CVE to CWE Root Cause Mapping Quick TipsMITRE CWE

Frequently Asked Questions

What is CWE-116: Improper Encoding or Escaping of Output?+

CWE-116: Improper Encoding or Escaping of Output is a Common Weakness Enumeration (CWE) entry maintained by MITRE. The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved. Improper encoding or escaping can allow attackers to change the commands that are sent to another component, inserting malicious commands instead. Most products follow a certain protocol that uses structured messages for communication between components, such as queries or commands. These structured messages can contain raw data interspersed with metadata or control information. For example, "GET /index.html HTTP/1.1" is a structured message containing a command ("GET") with a single argument ("/index.html") and metadata about which protocol version is being used ("HTTP/1.1"). If an application uses attacker-supplied inputs to construct a structured message without properly encoding or escaping, then the attacker could insert special characters that will cause the data to be interpreted as control information or metadata. Consequently, the component that receives the output will perform the wrong operations, or otherwise interpret the data incorrectly.

What are the security consequences of Improper Encoding or Escaping of Output?+

If exploited, CWE-116 (Improper Encoding or Escaping of Output) it can compromise Integrity, Confidentiality, Availability and Access Control, leading to outcomes such as Modify Application Data, Execute Unauthorized Code or Commands and Bypass Protection Mechanism.

How do you prevent or mitigate Improper Encoding or Escaping of Output?+

Recommended mitigations for CWE-116 include: Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messages. Study all expected communication protocols and data representations to determine the required encoding strategies. In some cases, input validation may be an important strategy when output encoding is not a complete solution. For example, you may be providing the same output that will be processed by multiple consumers that use different encodings or representations. In other cases, you may be required to allow user-supplied input to contain control information, such as limited HTML tags that support formatting in a wiki or bulletin board. When this type of requirement must be met, use an extremely strict allowlist to limit which control sequences can be used. Verify that the resulting syntactic structure is what you expect. Use your normal encoding methods for the remainder of the input. Use input validation as a defense-in-depth measure to reduce the likelihood of output encoding errors (see CWE-20).

Which programming languages are affected by Improper Encoding or Escaping of Output?+

CWE-116 commonly affects Not Language-Specific. Note that weaknesses are often language-agnostic patterns, so secure coding practices apply broadly.

What are real-world examples of Improper Encoding or Escaping of Output?+

MITRE documents real CVEs mapped to CWE-116, including CVE-2021-41232, CVE-2008-4636, CVE-2008-0769, CVE-2008-0005 and CVE-2008-5573. You can look up the full details of each CVE, including CVSS scores and remediation guidance, on our CVE Lookup tool.

What is the difference between a CWE and a CVE?+

A CWE (Common Weakness Enumeration) like CWE-116 describes a category of software weakness — the underlying flaw type. A CVE (Common Vulnerabilities and Exposures) identifies a specific, real-world vulnerability in a particular product. In short, a CWE is the kind of mistake, and a CVE is an instance of that mistake being found in software.

Learn More

Advertisement