CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controll
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (t
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP hea
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's H
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled inp
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadg
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra
Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. T
Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic
HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. Th
A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate res
Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the midd
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsou
Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arb
BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP
Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who
ewe is a Gleam web server. Prior to version 3.0.6, the encode_headers function in src/ewe/internal/encoder.gleam directl
transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject C
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize()
Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-te
Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b
tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera
Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacke
HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application h
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Htt
cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0, the chunked-response trailer output path writes
Frequently Asked Questions
What is CWE-113?
CWE-113 (CWE-113) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-113?
There are 43 CVE records associated with CWE-113 in our database. Of these, 3 are critical severity, 9 are high severity, and 20 are medium severity.
How can I protect against CWE-113 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-113 using AI-powered security agents.
Detect CWE-113 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-113 vulnerabilities across your infrastructure.
Get Started