Top 10 winner
Lost in Translation: Exploiting Unicode Normalization
Black Hat USA 2025 | Lost in Translation: Exploiting Unicode Normalization
How Unicode handling diverges between a front-end proxy or CDN and the back-end application. Decoding errors, overlong encodings, byte truncation, confusables, case mapping and combining diacritics all let input that passes validation normalize later into a different, dangerous string, defeating filters and enabling injection or account takeover.
Record
- Document
- Black Hat USA 2025 | Lost in Translation: Exploiting Unicode Normalization
- Researcher
- Ryan Barnett and Isabella Barnett
- Published by
- Black Hat
- Date
- Format
- Recording
- Topic
- Other
In the archive
Related sources
- Lost in Translation: Exploiting Unicode Normalization (Slides) Slides
- Lost in Translation: Exploiting Unicode Normalization
Tags
This page is the archive's own catalogue record. The research is the work of Ryan Barnett and Isabella Barnett, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .