Skip to main content

CWE archive

CWE-113 CVEs

Programmatic archive

107 CVEs tagged with CWE-1131 Critical, 23 High, 68 Medium, 15 Low, 0 Unrated.

CVE-2026-66753

Published Jul 28, 2026

tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-66746

Published Jul 28, 2026

Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D)…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-63771

Published Jul 20, 2026

Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwar…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-54163

Published Jul 17, 2026

secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives wit…

CVSS 4.7 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2025-62826

Published Jul 14, 2026

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62675

Published Jul 14, 2026

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4…

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50188

Published Jul 9, 2026

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(),…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2025-71381

Published Jun 30, 2026

Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request int…

CVSS 6.9 · Medium

CVE-2026-55766

Published Jun 23, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fiel…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50269

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to m…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-50630

Published Jun 12, 2026

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44489

Published Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49214

Published Jun 11, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43966

Published Jun 8, 2026

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP response splitting via non-VCHAR bytes…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
34.4

CVE-2026-48596

Published Jun 2, 2026

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.6

CVE-2026-38967

Published Jun 2, 2026

CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-38978

Published Jun 2, 2026

transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-47675

Published May 28, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options a…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9658

Published May 28, 2026

Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44214

Published May 26, 2026

eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42578

Published May 13, 2026

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with heade…

CVSS 2.9 · Low
evidence mentions
11
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-7010

Published May 11, 2026

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-42874

Published May 11, 2026

Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its string arguments, and in particular will not detect the pre…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-41683

Published May 8, 2026

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote use…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-43870

Published May 5, 2026

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/R…

CVSS 7.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 107 CVEsPage 1 of 5