CVE-2026-27120: Swift Html Escaping Grapheme Cluster Bypass
Using `String.replacing` or `String.replacingOccurrences` to escape HTML characters is vulnerable to extended grapheme cluster bypasses. An attacker can append Unicode combining scalars (e.g., U+0301) to HTML special characters (`<`, `>`, `&`, `"`, `'`), causing the replacement to fail and potentially leading to Cross-Site Scripting (XSS). To securely escape
greprules fetch cve-2026-27120-swift-html-escaping-grapheme-cluster-bypass --engine opengrepDescription
Using `String.replacing` or `String.replacingOccurrences` to escape HTML characters is vulnerable to extended grapheme cluster bypasses. An attacker can append Unicode combining scalars (e.g., U+0301) to HTML special characters (`<`, `>`, `&`, `"`, `'`), causing the replacement to fail and potentially leading to Cross-Site Scripting (XSS). To securely escape
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.