CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
107 vulnerabilities with CWE-113
CVE-2024-52875
HIGH
GFI Kerio Control 9.2.5-9.4.5 - HTTP Response Splitting via Dest Parameter
CVSS 8.8
CVE-2024-45687
LOW
Payara Platform <6.21.0 - HTTP Request/Response Splitting
CVE-2024-54021
MEDIUM
FortiOS 7.2.0-7.6.0 and FortiProxy 7.2.0-7.4.5 - Unauthenticated HTTP Response Splitting via Crafted Headers
CVSS 6.5
CVE-2024-42487
MEDIUM
Cilium <1.15.8-1.16.1 - Info Disclosure
CVSS 4.0
CVE-2024-40324
MEDIUM
E-Staff <5.1 - HTTP Response Splitting
CVSS 5.4
CVE-2024-20392
MEDIUM
Cisco AsyncOS - Unauthenticated HTTP Response Splitting via Web Management API
CVSS 6.1
CVE-2024-24795
MEDIUM
Apache HTTP Server 2.4.0-2.4.58 - HTTP Response Splitting via Malicious Response Headers
CVSS 6.3
CVE-2024-23644
MEDIUM
Trillium < 0.5.4 and trillium-http < 0.3.12 - HTTP Request/Response Splitting via Header Injection
CVSS 6.8
CVE-2023-48256
MEDIUM
Bosch NEXO-OS 1000-1500-sp2 - HTTP Response Splitting via Crafted URL
CVSS 5.3
CVE-2023-26147
MEDIUM
ithewei libhv - HTTP Response Splitting via CRLF Injection
CVSS 5.3
CVE-2023-42450
MEDIUM
Mastodon 4.2.0-beta1 to 4.2.0-rc1 - HTTP Request Injection
CVSS 5.4
CVE-2023-41834
MEDIUM
Apache Flink Stateful Functions 3.1.0-3.2.0 - HTTP Response Splitting via CRLF Injection
CVSS 6.1
CVE-2023-26142
MEDIUM
Crow - HTTP Response Splitting via Header CRLF Injection
CVSS 6.5
CVE-2023-26137
HIGH
drogon - HTTP Response Splitting via addHeader and addCookie Functions
CVSS 7.2
CVE-2023-34472
MEDIUM
AMI MegaRAC SPx BMC - HTTP Header Injection via CRLF Sequences
CVSS 5.7
CVE-2023-0508
LOW
GitLab 15.4.0-15.10.7, 15.11.0-15.11.6, 16.0.0-16.0.1 - HTTP Response Splitting via NPM Package API
CVSS 3.1
CVE-2023-32708
HIGH
Splunk Enterprise < 9.0.5, < 8.2.11, < 8.1.14 and Splunk Cloud Platform < 9.0.2303.100 - HTTP Response Splitting
CVSS 7.2
CVE-2022-42472
MEDIUM
FortiOS/FortiProxy HTTP Request Splitting (Auth Required)
CVSS 4.2
CVE-2022-37436
MEDIUM
Apache HTTP Server < 2.4.55 - HTTP Response Header Injection via CRLF Sequence
CVSS 5.3
CVE-2022-42471
MEDIUM
FortiWeb 6.3.6-6.3.20, 6.4.0-6.4.2, 7.0.0-7.0.2 - Authenticated HTTP Response Splitting
CVSS 5.4
CVE-2022-41915
MEDIUM
Netty 4.1.83-4.1.85 - HTTP Response Splitting via DefaultHttpHeaders.set Iterator
CVSS 6.5
CVE-2022-20772
MEDIUM
Cisco ESA/Secure Email and Web Manager - HTTP Response Splitting
CVSS 4.7
CVE-2022-3215
HIGH
SwiftNIO < 2.29.1 and 2.41.0-2.42.0 - HTTP Response Injection via CRLF in HTTP Headers
CVSS 7.5
CVE-2022-37953
MEDIUM
WorkstationST < 07.09.15 - HTTP Response Splitting via AM Gateway Challenge-Response Dialog
CVSS 4.7
CVE-2021-40336
MEDIUM
Hitachi Energy MSM <=2.2 - HTTP Response Splitting via Header Validation Failure
CVSS 5.0
Details
Vulnerabilities
107