The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
Volume of CVEs assigned to CWE-113 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
105 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52875HIGH An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expira | Jan 31, 2025 | 8.8 | 56 | NO | YES |
CVE-2022-37436MEDIUM Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. I | Jan 17, 2023 | 5.3 | 50 | NO | NO |
CVE-2026-38967CRITICAL CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. | Jun 2, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-42578HIGH Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header | May 13, 2026 | 7.5 | 33 | NO | NO |
CVE-2016-8024HIGH Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attack | Mar 14, 2017 | 8.1 | 33 | NO | YES |
CVE-2026-63771HIGH Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forward | Jul 20, 2026 | 7.1 | 32 | NO | NO |
CVE-2026-41683HIGH i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user | May 8, 2026 | 8.6 | 32 | NO | NO |
CVE-2026-42035HIGH Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) t | Apr 24, 2026 | 7.4 | 32 | NO | NO |
CVE-2026-50188MEDIUM Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), | Jul 9, 2026 | 6.9 | 30 | NO | NO |
CVE-2026-50269HIGH AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to mo | Jun 22, 2026 | 7.5 | 30 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.