Web Hack List

Top 10 winner

Lost in Translation: Exploiting Unicode Normalization

Black Hat USA 2025 | Lost in Translation: Exploiting Unicode Normalization

How Unicode handling diverges between a front-end proxy or CDN and the back-end application. Decoding errors, overlong encodings, byte truncation, confusables, case mapping and combining diacritics all let input that passes validation normalize later into a different, dangerous string, defeating filters and enabling injection or account takeover.

Record

Document
Black Hat USA 2025 | Lost in Translation: Exploiting Unicode Normalization
Researcher
Ryan Barnett and Isabella Barnett
Published by
Black Hat
Date
Format
Recording
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ryan Barnett and Isabella Barnett, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .