CWE-113— HTTP Response Splitting
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.— MITRE CWE catalog
111 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-113page 3 of 3
- CVE-2026-50576MEDIUMCVSS 6.8EG 6.82026-08-18
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration does not neutralize CRLF characters in values used by app/vau/VAUP…
- CVE-2026-50630MEDIUMCVSS 6.5EG 6.52026-06-12
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characte…
- CVE-2026-54163MEDIUMCVSS 4.7EG 4.72026-07-10
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_medi…
- CVE-2026-55766MEDIUMCVSS 4.8EG 4.82026-06-19
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reaso…
- CVE-2026-56762MEDIUMCVSS 5.3EG 5.32026-06-23
Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing invalid characters such as control characters (e.g. \r or \n) when an application passes a user…
- CVE-2026-63771HIGHCVSS 7.1EG 7.12026-07-20
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. A…
- CVE-2026-66746MEDIUMCVSS 5.4EG 5.42026-07-28
Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or line feed (0x0A) bytes into attacker-controlled input. A…
- CVE-2026-66753LOWCVSS 3.7EG 3.72026-07-28
tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides due to insufficient valid…
- CVE-2026-67289CRITICALCVSS 9.8EG 9.82026-08-01
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client c…
- CVE-2026-7010MEDIUMCVSS 6.5EG 6.52026-05-11
HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP…
- CVE-2026-9658HIGHCVSS 7.3EG 7.32026-05-28
Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header injections in the request paths unless they were double-enc…
Map vulnerabilities like CWE-113 to your infrastructure
EchelonGraph correlates every CVE — across CWE-113 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →