A vulnerability was found in Koji. It has been declared as critical. Affected is an unknown function of the component URL-Encoding Parser. Such manipulation leads to encoding error.

This vulnerability is referenced as CVE-2026-18376. It is possible to launch the attack remotely. No exploit is available.