CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
107 vulnerabilities with CWE-113
CVE-2026-34767
MEDIUM
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
CVSS 5.9
CVE-2026-34715
MEDIUM
ewe Has Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting)
CVSS 5.3
CVE-2026-34520
CRITICAL
AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass
CVSS 9.1
CVE-2026-34519
MEDIUM
AIOHTTP: HTTP response splitting via \r in reason phrase
CVSS 5.3
CVE-2026-34514
MEDIUM
AIOHTTP: CRLF injection in multipart part content type header construction
CVSS 5.3
CVE-2026-27810
MEDIUM
calibre <9.4.0 - HTTP Response Header Injection
CVSS 6.4
CVE-2026-24320
LOW
SAP NetWeaver AS ABAP Kernel - Memory Corruption via Crafted Input
CVSS 3.1
CVE-2026-23686
LOW
SAP NetWeaver Application Server Java - CRLF Injection
CVSS 3.4
CVE-2026-24489
MEDIUM
Gakido < 0.1.1 - HTTP Header Injection via CRLF Sequence
CVSS 5.3
CVE-2026-22779
MEDIUM
BlackSheep < 2.4.6 - HTTP Request/Response Splitting via CRLF Injection
CVSS 5.3
CVE-2025-62826
LOW
Fortinet FortiPAM - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSS 3.1
CVE-2025-62675
LOW
Fortinet FortiOS - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVSS 3.4
CVE-2025-71381
MEDIUM
Hono - Vary Header Injection in CORS Middleware
CVSS 6.5
CVE-2025-55271
LOW
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability
CVSS 3.1
CVE-2025-59151
HIGH
Pi-hole Web Interface < 6.3 - HTTP Response Splitting via .lp File Redirect
CVSS 8.2
CVE-2025-61689
HIGH
HTTP.jl <1.10.19 - CRLF-based Header Injection
CVE-2025-40927
HIGH
CGI::Simple < 1.282 - HTTP Response Splitting via URL-Encoded Parameter Injection
CVSS 7.3
CVE-2025-42934
MEDIUM
SAP S/4HANA Supplier invoice - Authenticated CRLF Injection via Trusted Sites Configuration
CVSS 4.3
CVE-2025-53094
HIGH
ESPAsyncWebServer <3.7.8 - CRLF Injection
CVE-2025-53007
HIGH
Arduino-esp32 <3.3.0-RC1, <3.2.1 - SSRF
CVE-2025-52479
HIGH
HTTP.jl <1.10.17 & URIs.jl <1.6.0 - CRLF Injection
CVE-2025-41234
MEDIUM
Spring Framework <6.0.5, 6.1.x, 6.2.x - RFD
CVSS 6.5
CVE-2025-30221
MEDIUM
Pitchfork <0.11.0 - HTTP Response Header Injection
CVSS 4.3
CVE-2025-0588
MEDIUM
Octopus Server 2020.1.0-2024.3.13097 - Denial of Service via Crafted Referrer Header
CVSS 4.9
CVE-2025-0825
MEDIUM
cpp-httplib 0.17.3-0.18.3 - HTTP Response Splitting via Null Byte Prefixed CRLF Injection
CVSS 5.3
Details
Vulnerabilities
107