Skip to content
Noroxi

CWE-113 · 102 records

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

CVEs in this class

102 records

  • An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.

    HighCVSS 8.8Proof of conceptEPSS 29%

    gfi · kerio controlJan 31, 2025

  • OnShift TurboGears HTTP Header controllers.py response splitting

    CriticalCVSS 9.8No exploitEPSS 1%

    turbogears project · turbogearsFeb 4, 2023

  • CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

    CriticalCVSS 9.8No exploitEPSS 1%

    Jun 2, 2026

  • Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting

    MediumCVSS 5.3No exploitEPSS 56%

    apache · http serverJan 17, 2023

  • FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection

    CriticalCVSS 9.3No exploitEPSS 1%

    freerdp · freerdpAug 1, 2026

  • A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"

    HighCVSS 8.8No exploitEPSS 2%

    siemens · simatic hmi comfort panels firmwareDec 13, 2018

  • CVE-2016-8024
    35Monitor

    Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earli

    HighCVSS 8.1Proof of conceptEPSS 9%

    mcafee · virusscan enterpriseMar 14, 2017

  • CVE-2018-0689
    35Monitor

    HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N

    HighCVSS 8.8No exploitEPSS 2%

    epson · ds-570w firmwareJan 9, 2019

  • The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.

    HighCVSS 8.8No exploitEPSS 1%

    yunohost · yunohostDec 4, 2018

  • HTTP Response Splitting via the ‘rest’ SPL Command

    HighCVSS 8.8No exploitEPSS 1%

    splunk · splunkJun 1, 2023

  • go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.

    HighCVSS 8.8No exploitEPSS 1%

    Aug 27, 2026

  • HTTP Response Splitting in Hitachi Energy’s MSM Product

    HighCVSS 8.8No exploitEPSS 0%

    hitachienergy · modular switchgear monitoring firmwareJul 25, 2022

  • arduino-esp32 vulnerable to CRLF injection in WebServer.cpp

    HighCVSS 8.9No exploitEPSS 0%

    espressif · arduino-esp32Jun 26, 2025

  • HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    hcltech · aftermarket cloudMar 26, 2026

  • CVE-2018-3911
    34Monitor

    An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.

    HighCVSS 8.6No exploitEPSS 1%

    samsung · sth-eth-250 firmwareAug 23, 2018

  • TIM Flow < 26.0.6 CRLF Injection via rt Parameter

    HighCVSS 8.5No exploitEPSS 0%

    tim solutions · tim flowAug 24, 2026

  • HTTP.jl vulnerable to Header injection/Response splitting via header construction.

    HighCVSS 8.7No exploitEPSS 0%

    juliaweb · http.jlOct 10, 2025

  • trillium-http and trillium-client vulnerable to HTTP Request/Response Splitting

    HighCVSS 8.1No exploitEPSS 1%

    trillium · trilliumJan 24, 2024

  • Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses

    HighCVSS 8.2No exploitEPSS 0%

    sanic-org · sanicSep 17, 2026

  • CVE-2020-5247
    31Monitor

    HTTP Response Splitting in Puma

    HighCVSS 7.5No exploitEPSS 3%

    puma · pumaFeb 28, 2020

  • CVE-2018-7830
    31Monitor

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in al

    HighCVSS 7.5No exploitEPSS 2%

    schneider-electric · modicom m340 firmwareNov 30, 2018

  • CVE-2022-3215
    30Monitor

    NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.

    HighCVSS 7.5No exploitEPSS 1%

    apple · swiftnioSep 28, 2022

  • Mastodon Server-Side Request Forgery vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    joinmastodon · mastodonSep 19, 2023

  • CVE-2015-1445
    29Monitor

    HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.

    HighCVSS 7.2No exploitEPSS 2%

    fli4l · fli4lAug 28, 2017

  • CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw

    HighCVSS 7.3No exploitEPSS 0%

    manwar · cgi::simpleAug 28, 2025

All vulnerability classes