CWE-113 · 102 kayıt
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
Bu sınıftaki CVE’ler
102 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2024-52875Kavram kanıtı | An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.gfi · kerio control · CWE-113 | Yüksek8,8 | — | %29,3 | 31 Oca 2025 |
39İzleyin | CVE-2019-25101İstismar yok | OnShift TurboGears HTTP Header controllers.py response splittingturbogears project · turbogears · CWE-113 | Kritik9,8 | — | %0,9 | 4 Şub 2023 |
39İzleyin | CVE-2026-38967İstismar yok | CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.CWE-113 | Kritik9,8 | — | %0,6 | 2 Haz 2026 |
38İzleyin | CVE-2022-37436İstismar yok | Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splittingapache · http server · CWE-113 | Orta5,3 | — | %55,9 | 17 Oca 2023 |
37İzleyin | CVE-2026-67289İstismar yok | FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirectionfreerdp · freerdp · CWE-113 | Kritik9,3 | — | %0,7 | 1 Ağu 2026 |
36İzleyin | CVE-2018-13814İstismar yok | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"siemens · simatic hmi comfort panels firmware · CWE-113 | Yüksek8,8 | — | %1,7 | 13 Ara 2018 |
35İzleyin | CVE-2016-8024Kavram kanıtı | Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlimcafee · virusscan enterprise · CWE-113 | Yüksek8,1 | — | %8,7 | 14 Mar 2017 |
35İzleyin | CVE-2018-0689İstismar yok | HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780Nepson · ds-570w firmware · CWE-113 | Yüksek8,8 | — | %1,6 | 9 Oca 2019 |
35İzleyin | CVE-2018-11347İstismar yok | The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.yunohost · yunohost · CWE-113 | Yüksek8,8 | — | %1,3 | 4 Ara 2018 |
35İzleyin | CVE-2023-32708İstismar yok | HTTP Response Splitting via the ‘rest’ SPL Commandsplunk · splunk · CWE-113 | Yüksek8,8 | — | %0,7 | 1 Haz 2023 |
35İzleyin | CVE-2026-75419İstismar yok | go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.CWE-113 | Yüksek8,8 | — | %0,5 | 27 Ağu 2026 |
35İzleyin | CVE-2021-40336İstismar yok | HTTP Response Splitting in Hitachi Energy’s MSM Producthitachienergy · modular switchgear monitoring firmware · CWE-113 | Yüksek8,8 | — | %0,5 | 25 Tem 2022 |
35İzleyin | CVE-2025-53007İstismar yok | arduino-esp32 vulnerable to CRLF injection in WebServer.cppespressif · arduino-esp32 · CWE-113 | Yüksek8,9 | — | %0,5 | 26 Haz 2025 |
35İzleyin | CVE-2025-55271İstismar yok | HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerabilityhcltech · aftermarket cloud · CWE-113 | Yüksek8,8 | — | %0,3 | 26 Mar 2026 |
34İzleyin | CVE-2018-3911İstismar yok | An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.samsung · sth-eth-250 firmware · CWE-113 | Yüksek8,6 | — | %1,2 | 23 Ağu 2018 |
34İzleyin | CVE-2026-39915İstismar yok | TIM Flow < 26.0.6 CRLF Injection via rt Parametertim solutions · tim flow · CWE-113 | Yüksek8,5 | — | %0,5 | 24 Ağu 2026 |
34İzleyin | CVE-2025-61689İstismar yok | HTTP.jl vulnerable to Header injection/Response splitting via header construction.juliaweb · http.jl · CWE-113 | Yüksek8,7 | — | %0,3 | 10 Eki 2025 |
32İzleyin | CVE-2024-23644İstismar yok | trillium-http and trillium-client vulnerable to HTTP Request/Response Splittingtrillium · trillium · CWE-113 | Yüksek8,1 | — | %0,6 | 24 Oca 2024 |
32İzleyin | CVE-2026-85077İstismar yok | Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responsessanic-org · sanic · CWE-113 | Yüksek8,2 | — | %0,5 | 17 Eyl 2026 |
31İzleyin | CVE-2020-5247İstismar yok | HTTP Response Splitting in Pumapuma · puma · CWE-113 | Yüksek7,5 | — | %2,5 | 28 Şub 2020 |
31İzleyin | CVE-2018-7830İstismar yok | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in alschneider-electric · modicom m340 firmware · CWE-113 | Yüksek7,5 | — | %2,4 | 30 Kas 2018 |
30İzleyin | CVE-2022-3215İstismar yok | NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.apple · swiftnio · CWE-113 | Yüksek7,5 | — | %0,6 | 28 Eyl 2022 |
30İzleyin | CVE-2023-42450İstismar yok | Mastodon Server-Side Request Forgery vulnerabilityjoinmastodon · mastodon · CWE-113 | Yüksek7,5 | — | %0,5 | 19 Eyl 2023 |
29İzleyin | CVE-2015-1445İstismar yok | HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.fli4l · fli4l · CWE-113 | Yüksek7,2 | — | %1,8 | 28 Ağu 2017 |
29İzleyin | CVE-2025-40927İstismar yok | CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flawmanwar · cgi::simple · CWE-113 | Yüksek7,3 | — | %0,5 | 28 Ağu 2025 |
- CVE-2024-5287544Planlayın
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.
YüksekCVSS 8,8Kavram kanıtıEPSS %29gfi · kerio control31 Oca 2025
- CVE-2019-2510139İzleyin
OnShift TurboGears HTTP Header controllers.py response splitting
KritikCVSS 9,8İstismar yokEPSS %1turbogears project · turbogears4 Şub 2023
- CVE-2026-3896739İzleyin
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
KritikCVSS 9,8İstismar yokEPSS %12 Haz 2026
- CVE-2022-3743638İzleyin
Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
OrtaCVSS 5,3İstismar yokEPSS %56apache · http server17 Oca 2023
- CVE-2026-6728937İzleyin
FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
KritikCVSS 9,3İstismar yokEPSS %1freerdp · freerdp1 Ağu 2026
- CVE-2018-1381436İzleyin
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15"
YüksekCVSS 8,8İstismar yokEPSS %2siemens · simatic hmi comfort panels firmware13 Ara 2018
- CVE-2016-802435İzleyin
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earli
YüksekCVSS 8,1Kavram kanıtıEPSS %9mcafee · virusscan enterprise14 Mar 2017
- CVE-2018-068935İzleyin
HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N
YüksekCVSS 8,8İstismar yokEPSS %2epson · ds-570w firmware9 Oca 2019
- CVE-2018-1134735İzleyin
The YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection.
YüksekCVSS 8,8İstismar yokEPSS %1yunohost · yunohost4 Ara 2018
- CVE-2023-3270835İzleyin
HTTP Response Splitting via the ‘rest’ SPL Command
YüksekCVSS 8,8İstismar yokEPSS %1splunk · splunk1 Haz 2023
- CVE-2026-7541935İzleyin
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %127 Ağu 2026
- CVE-2021-4033635İzleyin
HTTP Response Splitting in Hitachi Energy’s MSM Product
YüksekCVSS 8,8İstismar yokEPSS %0hitachienergy · modular switchgear monitoring firmware25 Tem 2022
- CVE-2025-5300735İzleyin
arduino-esp32 vulnerable to CRLF injection in WebServer.cpp
YüksekCVSS 8,9İstismar yokEPSS %0espressif · arduino-esp3226 Haz 2025
- CVE-2025-5527135İzleyin
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0hcltech · aftermarket cloud26 Mar 2026
- CVE-2018-391134İzleyin
An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.
YüksekCVSS 8,6İstismar yokEPSS %1samsung · sth-eth-250 firmware23 Ağu 2018
- CVE-2026-3991534İzleyin
TIM Flow < 26.0.6 CRLF Injection via rt Parameter
YüksekCVSS 8,5İstismar yokEPSS %0tim solutions · tim flow24 Ağu 2026
- CVE-2025-6168934İzleyin
HTTP.jl vulnerable to Header injection/Response splitting via header construction.
YüksekCVSS 8,7İstismar yokEPSS %0juliaweb · http.jl10 Eki 2025
- CVE-2024-2364432İzleyin
trillium-http and trillium-client vulnerable to HTTP Request/Response Splitting
YüksekCVSS 8,1İstismar yokEPSS %1trillium · trillium24 Oca 2024
- CVE-2026-8507732İzleyin
Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 responses
YüksekCVSS 8,2İstismar yokEPSS %0sanic-org · sanic17 Eyl 2026
- CVE-2020-524731İzleyin
HTTP Response Splitting in Puma
YüksekCVSS 7,5İstismar yokEPSS %3puma · puma28 Şub 2020
- CVE-2018-783031İzleyin
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in al
YüksekCVSS 7,5İstismar yokEPSS %2schneider-electric · modicom m340 firmware30 Kas 2018
- CVE-2022-321530İzleyin
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack.
YüksekCVSS 7,5İstismar yokEPSS %1apple · swiftnio28 Eyl 2022
- CVE-2023-4245030İzleyin
Mastodon Server-Side Request Forgery vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0joinmastodon · mastodon19 Eyl 2023
- CVE-2015-144529İzleyin
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
YüksekCVSS 7,2İstismar yokEPSS %2fli4l · fli4l28 Ağu 2017
- CVE-2025-4092729İzleyin
CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw
YüksekCVSS 7,3İstismar yokEPSS %0manwar · cgi::simple28 Ağu 2025