CWE-113
106 CVEs • Abstraction: Variant
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
CVEs (106)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Nodejs Suse2Linux Enterprise Node.jsMay 6, 2026 Oct 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP heade...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Wildfly Application ServerMay 6, 2026 Sep 26, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and con...Show more |
CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. |
CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF seq...Show more |
1Cisco 1Headend Digital Broadband Delivery System May 6, 2026 May 30, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the HTTP Header Handler in Digital Broadband Delivery System in Cisco Headend System Release allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting a...Show more |
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting at...Show more |