CWE-113: HTTP Request/Response Splitting
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
90 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-34520 — AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass
- CVE-2025-53007 — arduino-esp32 vulnerable to CRLF injection in WebServer.cpp
- CVE-2024-52875 — An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE
- CVE-2025-61689 — HTTP.jl vulnerable to Header injection/Response splitting via header construction.
- CVE-2025-53094 — ESPAsyncWebServer Vulnerable to CRLF Injection in AsyncWebHeader.cpp
- CVE-2025-59151 — Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection
- CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
- CVE-2026-41683 — HTTP response splitting and DoS in i18next-http-middleware via unsanitised Content-Language header
- CVE-2026-39915 — TIM Flow < 26.0.6 CRLF Injection via rt Parameter
- CVE-2025-0825 — CRLF injection in Cpp-httplib
- CVE-2024-23644 — trillium-http and trillium-client vulnerable to HTTP Request/Response Splitting
- CVE-2025-41234 — RFD Attack via “Content-Disposition” Header Sourced from Request
- CVE-2025-52479 — HTTP.jl vulnerable to CR/LF Injection in URIs
- CVE-2026-27810 — calibre Vulnerable to HTTP Response Header Injection
- CVE-2026-22779 — BlackSheep ClientSession is vulnerable to CRLF injection
- CVE-2026-42035 — Axios: Header Injection via Prototype Pollution
- CVE-2024-20392 — A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an
- CVE-2026-9658 — Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths
- CVE-2026-43870 — Apache Thrift: Node.js web_server.js multi-vulnerability
- CVE-2026-39971 — Serendipity: Host Header Injection leads to SMTP header injection via unvalidated HTTP_HOST
Recently published
- CVE-2026-77341 — cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writing
- CVE-2026-39915 — TIM Flow < 26.0.6 CRLF Injection via rt Parameter
- CVE-2026-50576 — ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests
- CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
- CVE-2026-66746 — Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
- CVE-2026-66753 — tiny-http 0.12.0 HTTP Response Splitting via Header Injection
- CVE-2026-63771 — Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
- CVE-2026-54163 — secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
- CVE-2025-62826 — An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera
- CVE-2025-62675 — An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera
- CVE-2026-50188 — Kirby: Request header injection in `Http\Remote`
- CVE-2025-71381 — Hono - Vary Header Injection in CORS Middleware
- CVE-2026-55766 — guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization
- CVE-2026-56762 — Hono - Missing Cookie Name Validation in setCookie()
- CVE-2026-50269 — AIOHTTP: CRLF injection in multipart headers
- CVE-2026-50630 — Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection
- CVE-2026-44489 — Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- CVE-2026-49214 — guzzlehttp/psr7 has CRLF Injection via URI Host Component
- CVE-2026-43966 — HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
- CVE-2026-48596 — CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection