← Vulnerability feed

Vulnerability record · CVE-2021-42694 · published 1 November 2021

CVE-2021-42694: Unicode code injection vulnerability

Unicode · Unicode

An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce source code identifiers such as function names using homoglyphs that render visually identical to a target identifier. Adversaries can leverage this to inject code via adversarial identifier definitions in upstream software dependencies invoked deceptively in downstream software. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard (all versions). Unless mitigated, an adversary could produce source code identifiers using homoglyph characters that render visually identical to but are distinct from a target identifier. In this way, an adversary could inject adversarial identifier definitions in upstream software that are not detected by human reviewers and are invoked deceptively in downstream software. The Unicode Consortium has documented this class of security vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms.

8.3 CVSS 3.1 High EPSS 4.9% · top 8.2% CWE-94 · Code injection
8.3CVSS 3.1 base score, v2 5.1
4.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce source code identifiers such as function names using homoglyphs that render visually identical to a target identifier. Adversaries can leverage this to inject code via adversarial identifier definitions in upstream software dependencies invoked deceptively in downstream software. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard (all versions). Unless mitigated, an adversary could produce source code identifiers using homoglyph characters that render visually identical to but are distinct from a target identifier. In this way, an adversary could inject adversarial identifier definitions in upstream software that are not detected by human reviewers and are invoked deceptively in downstream software. The Unicode Consortium has documented this class of security vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms.

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2021/11/01/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/11/01/6 Mailing ListThird Party Advisory
http://www.unicode.org/versions/Unicode14.0.0/ Release NotesVendor Advisory
https://cwe.mitre.org/data/definitions/1007.html Third Party Advisory
https://security.gentoo.org/glsa/202210-09 Third Party Advisory
https://trojansource.codes Third Party Advisory
https://www.kb.cert.org/vuls/id/999008 Third Party AdvisoryUS Government Resource
https://www.scyon.nl/post/trojans-in-your-source-code ExploitThird Party Advisory
https://www.unicode.org/reports/tr36/ Technical DescriptionVendor Advisory
https://www.unicode.org/reports/tr39/ Technical DescriptionVendor Advisory
http://www.openwall.com/lists/oss-security/2021/11/01/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/11/01/6 Mailing ListThird Party Advisory
http://www.unicode.org/versions/Unicode14.0.0/ Release NotesVendor Advisory
https://cwe.mitre.org/data/definitions/1007.html Third Party Advisory
https://security.gentoo.org/glsa/202210-09 Third Party Advisory
https://trojansource.codes Third Party Advisory
https://www.kb.cert.org/vuls/id/999008 Third Party AdvisoryUS Government Resource
https://www.scyon.nl/post/trojans-in-your-source-code ExploitThird Party Advisory
https://www.unicode.org/reports/tr36/ Technical DescriptionVendor Advisory
https://www.unicode.org/reports/tr39/ Technical DescriptionVendor Advisory

Track CVE-2021-42694 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2021-42694), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.