CWE-113 · 102 records
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVEs in this class
102 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2024-52875Proof of concept | An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.gfi · kerio control · CWE-113 | High8.8 | — | 29.3% | Jan 31, 2025 |
39Monitor | CVE-2019-25101No exploit | OnShift TurboGears HTTP Header controllers.py response splittingturbogears project · turbogears · CWE-113 | Critical9.8 | — | 0.9% | Feb 4, 2023 |
39Monitor | CVE-2026-38967No exploit | CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.CWE-113 | Critical9.8 | — | 0.6% | Jun 2, 2026 |
38Monitor | CVE-2022-37436No exploit | Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splittingapache · http server · CWE-113 | Medium5.3 | — | 55.9% | Jan 17, 2023 |
37Monitor | CVE-2026-67289No exploit | FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirectionfreerdp · freerdp · CWE-113 | Critical9.3 | — | 0.7% | Aug 1, 2026 |
36Monitor | CVE-2018-13814No exploit | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"siemens · simatic hmi comfort panels firmware · CWE-113 | High8.8 | — | 1.7% | Dec 13, 2018 |
35Monitor | CVE-2016-8024Proof of concept | Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlimcafee · virusscan enterprise · CWE-113 | High8.1 | — | 8.7% | Mar 14, 2017 |
35Monitor | CVE-2018-0689No exploit | HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780Nepson · ds-570w firmware · CWE-113 | High8.8 | — | 1.6% | Jan 9, 2019 |
35Monitor | CVE-2018-11347No exploit | The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.yunohost · yunohost · CWE-113 | High8.8 | — | 1.3% | Dec 4, 2018 |
35Monitor | CVE-2023-32708No exploit | HTTP Response Splitting via the ‘rest’ SPL Commandsplunk · splunk · CWE-113 | High8.8 | — | 0.7% | Jun 1, 2023 |
35Monitor | CVE-2026-75419No exploit | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.CWE-113 | High8.8 | — | 0.5% | Aug 27, 2026 |
35Monitor | CVE-2021-40336No exploit | HTTP Response Splitting in Hitachi Energy’s MSM Producthitachienergy · modular switchgear monitoring firmware · CWE-113 | High8.8 | — | 0.5% | Jul 25, 2022 |
35Monitor | CVE-2025-53007No exploit | arduino-esp32 vulnerable to CRLF injection in WebServer.cppespressif · arduino-esp32 · CWE-113 | High8.9 | — | 0.5% | Jun 26, 2025 |
35Monitor | CVE-2025-55271No exploit | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerabilityhcltech · aftermarket cloud · CWE-113 | High8.8 | — | 0.3% | Mar 26, 2026 |
34Monitor | CVE-2018-3911No exploit | An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.samsung · sth-eth-250 firmware · CWE-113 | High8.6 | — | 1.2% | Aug 23, 2018 |
34Monitor | CVE-2026-39915No exploit | TIM Flow < 26.0.6 CRLF Injection via rt Parametertim solutions · tim flow · CWE-113 | High8.5 | — | 0.5% | Aug 24, 2026 |
34Monitor | CVE-2025-61689No exploit | HTTP.jl vulnerable to Header injection/Response splitting via header construction.juliaweb · http.jl · CWE-113 | High8.7 | — | 0.3% | Oct 10, 2025 |
32Monitor | CVE-2024-23644No exploit | trillium-http and trillium-client vulnerable to HTTP Request/Response Splittingtrillium · trillium · CWE-113 | High8.1 | — | 0.6% | Jan 24, 2024 |
32Monitor | CVE-2026-85077No exploit | Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responsessanic-org · sanic · CWE-113 | High8.2 | — | 0.5% | Sep 17, 2026 |
31Monitor | CVE-2020-5247No exploit | HTTP Response Splitting in Pumapuma · puma · CWE-113 | High7.5 | — | 2.5% | Feb 28, 2020 |
31Monitor | CVE-2018-7830No exploit | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in alschneider-electric · modicom m340 firmware · CWE-113 | High7.5 | — | 2.4% | Nov 30, 2018 |
30Monitor | CVE-2022-3215No exploit | NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.apple · swiftnio · CWE-113 | High7.5 | — | 0.6% | Sep 28, 2022 |
30Monitor | CVE-2023-42450No exploit | Mastodon Server-Side Request Forgery vulnerabilityjoinmastodon · mastodon · CWE-113 | High7.5 | — | 0.5% | Sep 19, 2023 |
29Monitor | CVE-2015-1445No exploit | HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.fli4l · fli4l · CWE-113 | High7.2 | — | 1.8% | Aug 28, 2017 |
29Monitor | CVE-2025-40927No exploit | CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flawmanwar · cgi::simple · CWE-113 | High7.3 | — | 0.5% | Aug 28, 2025 |
- CVE-2024-5287544Plan
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.
HighCVSS 8.8Proof of conceptEPSS 29%gfi · kerio controlJan 31, 2025
- CVE-2019-2510139Monitor
OnShift TurboGears HTTP Header controllers.py response splitting
CriticalCVSS 9.8No exploitEPSS 1%turbogears project · turbogearsFeb 4, 2023
- CVE-2026-3896739Monitor
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
CriticalCVSS 9.8No exploitEPSS 1%Jun 2, 2026
- CVE-2022-3743638Monitor
Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
MediumCVSS 5.3No exploitEPSS 56%apache · http serverJan 17, 2023
- CVE-2026-6728937Monitor
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
CriticalCVSS 9.3No exploitEPSS 1%freerdp · freerdpAug 1, 2026
- CVE-2018-1381436Monitor
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"
HighCVSS 8.8No exploitEPSS 2%siemens · simatic hmi comfort panels firmwareDec 13, 2018
- CVE-2016-802435Monitor
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earli
HighCVSS 8.1Proof of conceptEPSS 9%mcafee · virusscan enterpriseMar 14, 2017
- CVE-2018-068935Monitor
HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N
HighCVSS 8.8No exploitEPSS 2%epson · ds-570w firmwareJan 9, 2019
- CVE-2018-1134735Monitor
The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.
HighCVSS 8.8No exploitEPSS 1%yunohost · yunohostDec 4, 2018
- CVE-2023-3270835Monitor
HTTP Response Splitting via the ‘rest’ SPL Command
HighCVSS 8.8No exploitEPSS 1%splunk · splunkJun 1, 2023
- CVE-2026-7541935Monitor
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.
HighCVSS 8.8No exploitEPSS 1%Aug 27, 2026
- CVE-2021-4033635Monitor
HTTP Response Splitting in Hitachi Energy’s MSM Product
HighCVSS 8.8No exploitEPSS 0%hitachienergy · modular switchgear monitoring firmwareJul 25, 2022
- CVE-2025-5300735Monitor
arduino-esp32 vulnerable to CRLF injection in WebServer.cpp
HighCVSS 8.9No exploitEPSS 0%espressif · arduino-esp32Jun 26, 2025
- CVE-2025-5527135Monitor
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability
HighCVSS 8.8No exploitEPSS 0%hcltech · aftermarket cloudMar 26, 2026
- CVE-2018-391134Monitor
An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.
HighCVSS 8.6No exploitEPSS 1%samsung · sth-eth-250 firmwareAug 23, 2018
- CVE-2026-3991534Monitor
TIM Flow < 26.0.6 CRLF Injection via rt Parameter
HighCVSS 8.5No exploitEPSS 0%tim solutions · tim flowAug 24, 2026
- CVE-2025-6168934Monitor
HTTP.jl vulnerable to Header injection/Response splitting via header construction.
HighCVSS 8.7No exploitEPSS 0%juliaweb · http.jlOct 10, 2025
- CVE-2024-2364432Monitor
trillium-http and trillium-client vulnerable to HTTP Request/Response Splitting
HighCVSS 8.1No exploitEPSS 1%trillium · trilliumJan 24, 2024
- CVE-2026-8507732Monitor
Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses
HighCVSS 8.2No exploitEPSS 0%sanic-org · sanicSep 17, 2026
- CVE-2020-524731Monitor
HTTP Response Splitting in Puma
HighCVSS 7.5No exploitEPSS 3%puma · pumaFeb 28, 2020
- CVE-2018-783031Monitor
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in al
HighCVSS 7.5No exploitEPSS 2%schneider-electric · modicom m340 firmwareNov 30, 2018
- CVE-2022-321530Monitor
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.
HighCVSS 7.5No exploitEPSS 1%apple · swiftnioSep 28, 2022
- CVE-2023-4245030Monitor
Mastodon Server-Side Request Forgery vulnerability
HighCVSS 7.5No exploitEPSS 0%joinmastodon · mastodonSep 19, 2023
- CVE-2015-144529Monitor
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
HighCVSS 7.2No exploitEPSS 2%fli4l · fli4lAug 28, 2017
- CVE-2025-4092729Monitor
CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw
HighCVSS 7.3No exploitEPSS 0%manwar · cgi::simpleAug 28, 2025