A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain
A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Pro
JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attacke
@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection head
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the develop
Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator
IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows is vulnerable to
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper v
IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 th
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to
A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 throu
A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa
IBM Aspera Faspex 5 5.0.0 through 5.0.14.3 is vulnerable to HTTP header injection, caused by improper validation of inpu
IBM Aspera Orchestrator 3.0.0 through 4.1.2 is vulnerable to HTTP header injection, caused by improper validation of inp
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by
The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A
HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially re
Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using special
Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above,
Frequently Asked Questions
What is CWE-644?
CWE-644 (CWE-644) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-644?
There are 27 CVE records associated with CWE-644 in our database. Of these, 2 are critical severity, 7 are high severity, and 14 are medium severity.
How can I protect against CWE-644 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-644 using AI-powered security agents.
Detect CWE-644 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-644 vulnerabilities across your infrastructure.
Get Started