CWE-113 · 102 записей
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CVE этого класса
102 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2024-52875Proof of concept | An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.gfi · kerio control · CWE-113 | Высокая8,8 | — | 29,3 % | 31 янв. 2025 г. |
39Наблюдать | CVE-2019-25101Эксплойта нет | OnShift TurboGears HTTP Header controllers.py response splittingturbogears project · turbogears · CWE-113 | Критическая9,8 | — | 0,9 % | 4 февр. 2023 г. |
39Наблюдать | CVE-2026-38967Эксплойта нет | CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.CWE-113 | Критическая9,8 | — | 0,6 % | 2 июн. 2026 г. |
38Наблюдать | CVE-2022-37436Эксплойта нет | Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splittingapache · http server · CWE-113 | Средняя5,3 | — | 55,9 % | 17 янв. 2023 г. |
37Наблюдать | CVE-2026-67289Эксплойта нет | FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirectionfreerdp · freerdp · CWE-113 | Критическая9,3 | — | 0,7 % | 1 авг. 2026 г. |
36Наблюдать | CVE-2018-13814Эксплойта нет | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"siemens · simatic hmi comfort panels firmware · CWE-113 | Высокая8,8 | — | 1,7 % | 13 дек. 2018 г. |
35Наблюдать | CVE-2016-8024Proof of concept | Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlimcafee · virusscan enterprise · CWE-113 | Высокая8,1 | — | 8,7 % | 14 мар. 2017 г. |
35Наблюдать | CVE-2018-0689Эксплойта нет | HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780Nepson · ds-570w firmware · CWE-113 | Высокая8,8 | — | 1,6 % | 9 янв. 2019 г. |
35Наблюдать | CVE-2018-11347Эксплойта нет | The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.yunohost · yunohost · CWE-113 | Высокая8,8 | — | 1,3 % | 4 дек. 2018 г. |
35Наблюдать | CVE-2023-32708Эксплойта нет | HTTP Response Splitting via the ‘rest’ SPL Commandsplunk · splunk · CWE-113 | Высокая8,8 | — | 0,7 % | 1 июн. 2023 г. |
35Наблюдать | CVE-2026-75419Эксплойта нет | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.CWE-113 | Высокая8,8 | — | 0,5 % | 27 авг. 2026 г. |
35Наблюдать | CVE-2021-40336Эксплойта нет | HTTP Response Splitting in Hitachi Energy’s MSM Producthitachienergy · modular switchgear monitoring firmware · CWE-113 | Высокая8,8 | — | 0,5 % | 25 июл. 2022 г. |
35Наблюдать | CVE-2025-53007Эксплойта нет | arduino-esp32 vulnerable to CRLF injection in WebServer.cppespressif · arduino-esp32 · CWE-113 | Высокая8,9 | — | 0,5 % | 26 июн. 2025 г. |
35Наблюдать | CVE-2025-55271Эксплойта нет | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerabilityhcltech · aftermarket cloud · CWE-113 | Высокая8,8 | — | 0,3 % | 26 мар. 2026 г. |
34Наблюдать | CVE-2018-3911Эксплойта нет | An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.samsung · sth-eth-250 firmware · CWE-113 | Высокая8,6 | — | 1,2 % | 23 авг. 2018 г. |
34Наблюдать | CVE-2026-39915Эксплойта нет | TIM Flow < 26.0.6 CRLF Injection via rt Parametertim solutions · tim flow · CWE-113 | Высокая8,5 | — | 0,5 % | 24 авг. 2026 г. |
34Наблюдать | CVE-2025-61689Эксплойта нет | HTTP.jl vulnerable to Header injection/Response splitting via header construction.juliaweb · http.jl · CWE-113 | Высокая8,7 | — | 0,3 % | 10 окт. 2025 г. |
32Наблюдать | CVE-2024-23644Эксплойта нет | trillium-http and trillium-client vulnerable to HTTP Request/Response Splittingtrillium · trillium · CWE-113 | Высокая8,1 | — | 0,6 % | 24 янв. 2024 г. |
32Наблюдать | CVE-2026-85077Эксплойта нет | Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responsessanic-org · sanic · CWE-113 | Высокая8,2 | — | 0,5 % | 17 сент. 2026 г. |
31Наблюдать | CVE-2020-5247Эксплойта нет | HTTP Response Splitting in Pumapuma · puma · CWE-113 | Высокая7,5 | — | 2,5 % | 28 февр. 2020 г. |
31Наблюдать | CVE-2018-7830Эксплойта нет | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in alschneider-electric · modicom m340 firmware · CWE-113 | Высокая7,5 | — | 2,4 % | 30 нояб. 2018 г. |
30Наблюдать | CVE-2022-3215Эксплойта нет | NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.apple · swiftnio · CWE-113 | Высокая7,5 | — | 0,6 % | 28 сент. 2022 г. |
30Наблюдать | CVE-2023-42450Эксплойта нет | Mastodon Server-Side Request Forgery vulnerabilityjoinmastodon · mastodon · CWE-113 | Высокая7,5 | — | 0,5 % | 19 сент. 2023 г. |
29Наблюдать | CVE-2015-1445Эксплойта нет | HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.fli4l · fli4l · CWE-113 | Высокая7,2 | — | 1,8 % | 28 авг. 2017 г. |
29Наблюдать | CVE-2025-40927Эксплойта нет | CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flawmanwar · cgi::simple · CWE-113 | Высокая7,3 | — | 0,5 % | 28 авг. 2025 г. |
- CVE-2024-5287544В плане
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.
ВысокаяCVSS 8,8Proof of conceptEPSS 29 %gfi · kerio control31 янв. 2025 г.
- CVE-2019-2510139Наблюдать
OnShift TurboGears HTTP Header controllers.py response splitting
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %turbogears project · turbogears4 февр. 2023 г.
- CVE-2026-3896739Наблюдать
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %2 июн. 2026 г.
- CVE-2022-3743638Наблюдать
Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
СредняяCVSS 5,3Эксплойта нетEPSS 56 %apache · http server17 янв. 2023 г.
- CVE-2026-6728937Наблюдать
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %freerdp · freerdp1 авг. 2026 г.
- CVE-2018-1381436Наблюдать
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %siemens · simatic hmi comfort panels firmware13 дек. 2018 г.
- CVE-2016-802435Наблюдать
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earli
ВысокаяCVSS 8,1Proof of conceptEPSS 9 %mcafee · virusscan enterprise14 мар. 2017 г.
- CVE-2018-068935Наблюдать
HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %epson · ds-570w firmware9 янв. 2019 г.
- CVE-2018-1134735Наблюдать
The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %yunohost · yunohost4 дек. 2018 г.
- CVE-2023-3270835Наблюдать
HTTP Response Splitting via the ‘rest’ SPL Command
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %splunk · splunk1 июн. 2023 г.
- CVE-2026-7541935Наблюдать
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %27 авг. 2026 г.
- CVE-2021-4033635Наблюдать
HTTP Response Splitting in Hitachi Energy’s MSM Product
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %hitachienergy · modular switchgear monitoring firmware25 июл. 2022 г.
- CVE-2025-5300735Наблюдать
arduino-esp32 vulnerable to CRLF injection in WebServer.cpp
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %espressif · arduino-esp3226 июн. 2025 г.
- CVE-2025-5527135Наблюдать
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %hcltech · aftermarket cloud26 мар. 2026 г.
- CVE-2018-391134Наблюдать
An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %samsung · sth-eth-250 firmware23 авг. 2018 г.
- CVE-2026-3991534Наблюдать
TIM Flow < 26.0.6 CRLF Injection via rt Parameter
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %tim solutions · tim flow24 авг. 2026 г.
- CVE-2025-6168934Наблюдать
HTTP.jl vulnerable to Header injection/Response splitting via header construction.
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %juliaweb · http.jl10 окт. 2025 г.
- CVE-2024-2364432Наблюдать
trillium-http and trillium-client vulnerable to HTTP Request/Response Splitting
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %trillium · trillium24 янв. 2024 г.
- CVE-2026-8507732Наблюдать
Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %sanic-org · sanic17 сент. 2026 г.
- CVE-2020-524731Наблюдать
HTTP Response Splitting in Puma
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %puma · puma28 февр. 2020 г.
- CVE-2018-783031Наблюдать
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in al
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %schneider-electric · modicom m340 firmware30 нояб. 2018 г.
- CVE-2022-321530Наблюдать
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %apple · swiftnio28 сент. 2022 г.
- CVE-2023-4245030Наблюдать
Mastodon Server-Side Request Forgery vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %joinmastodon · mastodon19 сент. 2023 г.
- CVE-2015-144529Наблюдать
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %fli4l · fli4l28 авг. 2017 г.
- CVE-2025-4092729Наблюдать
CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %manwar · cgi::simple28 авг. 2025 г.