CWE-113: CWE-113

11
Total CVEs
0
Critical
4
High
5.7
Avg CVSS

Yearly Trend

2026
3
2025
5
2024
1
2023
2

Top Affected Vendors

1 Sap 2
2 Yhirose 1
3 Neoteroi 1
4 Cisco 1
5 Splunk 1
6 Gfi 1
7 Octopus 1
8 Drogon 1

All CWE-113 CVEs (11)

CVE-2024-52875
8.8

This vulnerability in GFI Kerio Control allows attackers to perform open redirect, HTTP response splitting, and reflected cross-site scripting (XSS) a...

Jan 31, 2025
CVE-2025-40927
7.3

CVE-2025-40927 is an HTTP response splitting vulnerability in CGI::Simple for Perl that allows attackers to inject malicious content into HTTP respons...

Aug 29, 2025
CVE-2023-26137
7.2

CVE-2023-26137 is an HTTP response splitting vulnerability in the Drogon C++ web framework. Attackers can inject malicious content into HTTP responses...

Jul 6, 2023
CVE-2023-32708
7.2

This CVE describes an HTTP response splitting vulnerability in Splunk's 'rest' SPL command that allows low-privileged users to potentially access arbi...

Jun 1, 2023
CVE-2024-20392
6.1

An HTTP response splitting vulnerability in Cisco Secure Email Gateway's web management API allows unauthenticated attackers to conduct cross-site scr...

May 15, 2024
CVE-2026-22779
5.3

CVE-2026-22779 is a CRLF injection vulnerability in BlackSheep's HTTP Client implementation that allows attackers to modify HTTP requests by injecting...

Jan 14, 2026
CVE-2025-0825
5.3

CVE-2025-0825 is a CRLF injection vulnerability in cpp-httplib where null-byte-prefixed CRLF sequences aren't properly filtered, allowing attackers to...

Feb 4, 2025
CVE-2025-0588
4.9

This vulnerability in Octopus Server allows authenticated users with sufficient privileges to set custom headers that can cause server responses to re...

Feb 11, 2025
CVE-2025-30221
4.3

Pitchfork versions before 0.11.0 are vulnerable to HTTP Response Header Injection when used with Rack 3. This allows attackers to inject malicious hea...

Mar 27, 2025
CVE-2026-23686
3.4

This CRLF injection vulnerability in SAP NetWeaver Application Server Java allows authenticated administrators to inject malicious entries into config...

Feb 10, 2026
CVE-2026-24320
3.1

This vulnerability in SAP NetWeaver and ABAP Platform allows authenticated attackers to exploit memory management errors by sending specially crafted ...

Feb 10, 2026

About CWE-113 (CWE-113)

Our database tracks 11 CVEs classified as CWE-113, with 0 rated critical and 4 rated high severity. The average CVSS score for CWE-113 vulnerabilities is 5.7.

External reference: View CWE-113 on MITRE CWE →

Monitor CWE-113 Vulnerabilities

Get alerted when new CWE-113 CVEs affect your infrastructure.

Start Monitoring Free