CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
60 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-26234 — JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax
- CVE-2025-64484 — OAuth2-Proxy vulnerable to header smuggling via underscore, leading to potential privilege escalation
- CVE-2025-64425 — Coolify has host header injection in forgot password
- CVE-2024-10006 — Consul L7 Intentions Vulnerable To Headers Bypass
- CVE-2026-33149 — Tandoor Recipes Vulnerable to Host Header Injection
- CVE-2026-33805 — @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers
- CVE-2025-13803 — MediaCrush Header paths.py http headers for scripting syntax
- CVE-2024-1064 — Improper Neutralization of HTTP Headers for Scripting Syntax in Crafty Controller 4
- CVE-2024-47549 — Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of uninte
- CVE-2025-13434 — jameschz Hush Framework HTTP Host Header Util.php http headers for scripting syntax
- CVE-2026-48126 — Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
- CVE-2026-67179 — Genkit improper host header validation
- CVE-2025-27901 — Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
- CVE-2025-14807 — IBM InfoSphere Information Server is vulnerable to HTTP header injection
- CVE-2024-51451 — Multiple Vulnerabilities in IBM Concert Software
- CVE-2024-39736 — IBM Datacap Navigator HTTP HOST header injection
- CVE-2026-69183 — Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)
- CVE-2025-52647 — HCL BigFix WebUI is affected by a host header poisoning vulnerability
- CVE-2025-27632 — A Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value
- CVE-2026-55791 — Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Recently published
- CVE-2026-69183 — Monkeytype: Rate-limit and anti-brute-force controls bypassable via spoofed HTTP headers (forgotPasswordEmail/verificationEmail mail bombing and badAuth bypass)
- CVE-2026-67179 — Genkit improper host header validation
- CVE-2026-66778 — Multiple vulnerabilities in SAP Business AI Platform (Approuter)
- CVE-2026-72574 — picocms Pico - Host Header Injection Enables Script Source Hijacking
- CVE-2026-0516 — A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to
- CVE-2026-48061 — Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
- CVE-2026-21762 — Missing HTTP Security Headers in DevOps Loop
- CVE-2026-54477 — Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax
- CVE-2026-55791 — Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
- CVE-2024-51454 — IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed
- CVE-2026-10836 — Improper neutralization of HTTP headers in Password Manager
- CVE-2026-4096 — A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Injection attack due to improper handling of the Host header in HTTP requests.
- CVE-2026-48126 — Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
- CVE-2026-33805 — @fastify/reply-from vulnerable to connection header abuse enabling stripping of proxy-added headers
- CVE-2025-66485 — Multiple vulnerabilities have been addressed in IBM Aspera Shares
- CVE-2026-33149 — Tandoor Recipes Vulnerable to Host Header Injection
- CVE-2025-14807 — IBM InfoSphere Information Server is vulnerable to HTTP header injection
- CVE-2025-13213 — Multiple vulnerabilities in IBM Aspera Orchestrator
- CVE-2025-36227 — Multiple vulnerabilities in IBM Aspera Faspex
- CVE-2026-1698 — HTTP Host header vulnerability in WebClient and WebScheduler web apps