CWE-113

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

Parent: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.

107 vulnerabilities with CWE-113
CVE-2024-52875 HIGH
GFI Kerio Control 9.2.5-9.4.5 - HTTP Response Splitting via Dest Parameter
CVSS 8.8
CVE-2024-45687 LOW
Payara Platform <6.21.0 - HTTP Request/Response Splitting
CVE-2024-54021 MEDIUM
FortiOS 7.2.0-7.6.0 and FortiProxy 7.2.0-7.4.5 - Unauthenticated HTTP Response Splitting via Crafted Headers
CVSS 6.5
CVE-2024-42487 MEDIUM
Cilium <1.15.8-1.16.1 - Info Disclosure
CVSS 4.0
CVE-2024-40324 MEDIUM
E-Staff <5.1 - HTTP Response Splitting
CVSS 5.4
CVE-2024-20392 MEDIUM
Cisco AsyncOS - Unauthenticated HTTP Response Splitting via Web Management API
CVSS 6.1
CVE-2024-24795 MEDIUM
Apache HTTP Server 2.4.0-2.4.58 - HTTP Response Splitting via Malicious Response Headers
CVSS 6.3
CVE-2024-23644 MEDIUM
Trillium < 0.5.4 and trillium-http < 0.3.12 - HTTP Request/Response Splitting via Header Injection
CVSS 6.8
CVE-2023-48256 MEDIUM
Bosch NEXO-OS 1000-1500-sp2 - HTTP Response Splitting via Crafted URL
CVSS 5.3
CVE-2023-26147 MEDIUM
ithewei libhv - HTTP Response Splitting via CRLF Injection
CVSS 5.3
CVE-2023-42450 MEDIUM
Mastodon 4.2.0-beta1 to 4.2.0-rc1 - HTTP Request Injection
CVSS 5.4
CVE-2023-41834 MEDIUM
Apache Flink Stateful Functions 3.1.0-3.2.0 - HTTP Response Splitting via CRLF Injection
CVSS 6.1
CVE-2023-26142 MEDIUM
Crow - HTTP Response Splitting via Header CRLF Injection
CVSS 6.5
CVE-2023-26137 HIGH
drogon - HTTP Response Splitting via addHeader and addCookie Functions
CVSS 7.2
CVE-2023-34472 MEDIUM
AMI MegaRAC SPx BMC - HTTP Header Injection via CRLF Sequences
CVSS 5.7
CVE-2023-0508 LOW
GitLab 15.4.0-15.10.7, 15.11.0-15.11.6, 16.0.0-16.0.1 - HTTP Response Splitting via NPM Package API
CVSS 3.1
CVE-2023-32708 HIGH
Splunk Enterprise < 9.0.5, < 8.2.11, < 8.1.14 and Splunk Cloud Platform < 9.0.2303.100 - HTTP Response Splitting
CVSS 7.2
CVE-2022-42472 MEDIUM
FortiOS/FortiProxy HTTP Request Splitting (Auth Required)
CVSS 4.2
CVE-2022-37436 MEDIUM
Apache HTTP Server < 2.4.55 - HTTP Response Header Injection via CRLF Sequence
CVSS 5.3
CVE-2022-42471 MEDIUM
FortiWeb 6.3.6-6.3.20, 6.4.0-6.4.2, 7.0.0-7.0.2 - Authenticated HTTP Response Splitting
CVSS 5.4
CVE-2022-41915 MEDIUM
Netty 4.1.83-4.1.85 - HTTP Response Splitting via DefaultHttpHeaders.set Iterator
CVSS 6.5
CVE-2022-20772 MEDIUM
Cisco ESA/Secure Email and Web Manager - HTTP Response Splitting
CVSS 4.7
CVE-2022-3215 HIGH
SwiftNIO < 2.29.1 and 2.41.0-2.42.0 - HTTP Response Injection via CRLF in HTTP Headers
CVSS 7.5
CVE-2022-37953 MEDIUM
WorkstationST < 07.09.15 - HTTP Response Splitting via AM Gateway Challenge-Response Dialog
CVSS 4.7
CVE-2021-40336 MEDIUM
Hitachi Energy MSM <=2.2 - HTTP Response Splitting via Header Validation Failure
CVSS 5.0
Details
Vulnerabilities 107