The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
Volume of CVEs assigned to CWE-644 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
58 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55791MEDIUM Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forge | Jul 2, 2026 | 6.9 | 33 | NO | NO |
CVE-2026-33805HIGH @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequ | Apr 15, 2026 | 8.6 | 33 | NO | NO |
CVE-2025-52660CRITICAL HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise. | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-70948CRITICAL A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing th | Mar 5, 2026 | 9.3 | 31 | NO | NO |
CVE-2025-64484HIGH OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In v | Nov 10, 2025 | 8.5 | 30 | NO | NO |
CVE-2026-48126HIGH Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.g | May 26, 2026 | 8.2 | 29 | NO | NO |
CVE-2026-26234HIGH JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in | Feb 12, 2026 | 8.8 | 29 | NO | NO |
CVE-2017-6031HIGH A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been ident | May 6, 2017 | 8.8 | 29 | NO | NO |
CVE-2026-54477MEDIUM The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. | Jul 3, 2026 | 5.4 | 28 | NO | NO |
CVE-2026-33149HIGH Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which ca | Mar 26, 2026 | 8.1 | 28 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.