CWE-113

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

Parent: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.

82 vulnerabilities with CWE-113
CVE-2026-42035 HIGH
Axios: Header Injection via Prototype Pollution
CVSS 7.4
CVE-2026-39971 HIGH
Serendipity: Host Header Injection leads to SMTP header injection via unvalidated HTTP_HOST
CVSS 7.2
CVE-2026-40175 MEDIUM
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 4.8
CVE-2026-34767 MEDIUM
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
CVSS 5.9
CVE-2026-34715 MEDIUM
ewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting)
CVSS 5.3
CVE-2026-34520 CRITICAL
AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass
CVSS 9.1
CVE-2026-34519 MEDIUM
AIOHTTP: HTTP response splitting via \r in reason phrase
CVSS 5.3
CVE-2026-34514 MEDIUM
AIOHTTP: CRLF injection in multipart part content type header construction
CVSS 5.3
CVE-2026-27810 MEDIUM
calibre <9.4.0 - HTTP Response Header Injection
CVSS 6.4
CVE-2026-24320 LOW
SAP NetWeaver - Memory Corruption
CVSS 3.1
CVE-2026-23686 LOW
SAP NetWeaver Application Server Java - CRLF Injection
CVSS 3.4
CVE-2026-24489 MEDIUM
Gakido <0.1.1 - Command Injection
CVSS 5.3
CVE-2026-22779 MEDIUM
BlackSheep <2.4.6 - CRLF Injection
CVSS 5.3
CVE-2025-55271 LOW
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability
CVSS 3.1
CVE-2025-59151 HIGH
Pi-hole Web Interface < 6.3 - XSS
CVSS 8.2
CVE-2025-61689 HIGH
HTTP.jl <1.10.19 - CRLF-based Header Injection
CVE-2025-40927 HIGH
CGI::Simple <1.282 - XSS
CVSS 7.3
CVE-2025-42934 MEDIUM
SAP S/4HANA - CRLF Injection
CVSS 4.3
CVE-2025-53094 HIGH
ESPAsyncWebServer <3.7.8 - CRLF Injection
CVE-2025-53007 HIGH
Arduino-esp32 <3.3.0-RC1, <3.2.1 - SSRF
CVE-2025-52479 HIGH
HTTP.jl <1.10.17 & URIs.jl <1.6.0 - CRLF Injection
CVE-2025-41234 MEDIUM
Spring Framework <6.0.5, 6.1.x, 6.2.x - RFD
CVSS 6.5
CVE-2025-30221 MEDIUM
Pitchfork <0.11.0 - HTTP Response Header Injection
CVSS 4.3
CVE-2025-0588 MEDIUM
Octopus Server - DoS
CVSS 4.9
CVE-2025-0825 MEDIUM
Yhirose Cpp-httplib < 0.18.4 - XSS
CVSS 5.3
Details
Vulnerabilities 82