CWE-644— Improper Neutralization of HTTP Headers for Scripting Syntax
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.— MITRE CWE catalog
68 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-644page 2 of 2
- CVE-2025-70948CRITICALCVSS 9.3EG 9.32026-03-05
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.
- CVE-2026-0516MEDIUMCVSS 6.5EG 6.52026-08-05
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
- CVE-2026-10836MEDIUMCVSS 5.1EG 5.12026-06-17
Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A successful exploit could result in the generation of manipulated links or responses, potentially…
- CVE-2026-1698MEDIUMCVSS 6.1EG 6.12026-02-26
A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This v…
- CVE-2026-21762MEDIUMCVSS 5.3EG 5.32026-07-17
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.
- CVE-2026-26234HIGHCVSS 8.8EG 8.82026-02-12
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate prox…
- CVE-2026-26747CRITICALCVSS 9.1EG 9.12026-02-20
A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and defa…
- CVE-2026-33149HIGHCVSS 8.1EG 8.12026-03-26
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the HTTP Host header wit…
- CVE-2026-33805HIGHCVSS 8.6EG 8.62026-04-15
@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This allows attackers to retroactively strip pr…
- CVE-2026-4096MEDIUMCVSS 6.1EG 6.52026-06-11
IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-…
- CVE-2026-48061MEDIUMCVSS 5.9EG 5.92026-06-10
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelist…
- CVE-2026-48126HIGHCVSS 8.2EG 8.22026-05-26
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory b…
- CVE-2026-54477MEDIUMCVSS 5.4EG 5.42026-07-03
The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
- CVE-2026-55791MEDIUMCVSS 6.9EG 6.92026-06-19
Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /a…
- CVE-2026-66778MEDIUMCVSS 5.3EG 5.32026-08-11
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information.…
- CVE-2026-67179HIGHCVSS 7.8EG 7.82026-08-11
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any r…
- CVE-2026-69183HIGHCVSS 7.5EG 7.52026-08-20
Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the…
- CVE-2026-72574MEDIUMCVSS 6.1EG 6.12026-08-10
A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control the origin of JavaScript and CSS assets loaded by the default theme. When base_url is unset (the default), Pico::getBa…
Map vulnerabilities like CWE-644 to your infrastructure
EchelonGraph correlates every CVE — across CWE-644 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →