CWE-644: CWE-644

19
Total CVEs
1
Critical
7
High
6.7
Avg CVSS

Yearly Trend

2026
5
2025
8
2024
4
2023
2

Top Affected Vendors

1 Ibm 7
2 Dell 1
3 Coollabs 1
4 Hcltech 1
5 Sap 1
6 Craftycontrol 1
7 Jameschz 1
8 Jung Group 1

All CWE-644 CVEs (19)

CVE-2023-47143
10.0

IBM Tivoli Application Dependency Discovery Manager versions 7.3.0.0 through 7.3.0.10 are vulnerable to HTTP header injection due to improper validati...

Feb 2, 2024
CVE-2026-26234
8.8

JUNG Smart Visu Server 1.1.1050 has a request header manipulation vulnerability where unauthenticated attackers can inject arbitrary values in the X-F...

Feb 12, 2026
CVE-2023-32465
8.8

CVE-2023-32465 is an authentication bypass vulnerability in Dell PowerProtect Cyber Recovery that allows attackers to gain unauthorized admin access t...

Jun 14, 2023
CVE-2025-64484
8.5

This vulnerability allows authenticated users to bypass OAuth2-Proxy's header filtering by using underscores instead of dashes in X-Forwarded-* header...

Nov 10, 2025
CVE-2025-64425
8.1

This vulnerability in Coolify allows attackers to hijack password reset emails by manipulating the host header. When victims click malicious reset lin...

Jan 5, 2026
CVE-2024-1064
7.5

CVE-2024-1064 is a host header injection vulnerability in Crafty Controller's HTTP handler that allows unauthenticated remote attackers to cause a Den...

Feb 3, 2024
CVE-2025-13803
7.3

MediaCrush 1.0.0 and 1.0.1 contain an HTTP header injection vulnerability in the Host header handling component. Attackers can inject malicious script...

Dec 1, 2025
CVE-2023-36921
7.2

This vulnerability in SAP Solution Manager's Diagnostics agent allows attackers to tamper with request headers, potentially poisoning content served t...

Jul 11, 2023
CVE-2025-27901
6.5

IBM DB2 Recovery Expert for LUW 5.5 is vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attackers to inject...

Feb 17, 2026
CVE-2024-51451
6.5

IBM Concert versions 1.0.0 through 2.1.0 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attackers to ...

Feb 4, 2026
CVE-2024-39736
6.5

IBM Datacap Navigator versions 9.1.5 through 9.1.9 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows att...

Jul 15, 2024
CVE-2025-52647
6.1

BigFix WebUI is vulnerable to Host Header Poisoning attacks where attackers can manipulate HTTP Host headers to redirect users to malicious sites or b...

Oct 10, 2025
CVE-2025-23001
6.1

A Host header injection vulnerability in CTFd 3.7.5 allows attackers to manipulate the Host header in HTTP requests. This can lead to phishing attacks...

Jan 31, 2025
CVE-2025-36223
5.4

IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attackers to inject malicious...

Nov 12, 2025
CVE-2022-43847
5.4

IBM Aspera Console versions 3.4.0 through 3.4.4 are vulnerable to HTTP header injection due to improper validation of HOST headers. This allows attack...

Apr 14, 2025
CVE-2025-13434
5.3

CVE-2025-13434 is a vulnerability in jameschz Hush Framework 2.0 where improper neutralization of the HTTP Host header allows remote attackers to inje...

Nov 20, 2025
CVE-2025-0154
5.3

IBM TXSeries for Multiplatforms versions 9.1 and 11.1 have an HTTP header injection vulnerability that could allow remote attackers to read sensitive ...

Apr 2, 2025
CVE-2024-30129
5.3

CVE-2024-30129 is an HTTP host header manipulation vulnerability in HCL software that allows attackers to redirect requests to different domains/IP ad...

Dec 6, 2024
CVE-2025-52660
2.7

HCL AION has an unrestricted file upload vulnerability that allows attackers to upload malicious files. This could lead to remote code execution or sy...

Jan 19, 2026

About CWE-644 (CWE-644)

Our database tracks 19 CVEs classified as CWE-644, with 1 rated critical and 7 rated high severity. The average CVSS score for CWE-644 vulnerabilities is 6.7.

External reference: View CWE-644 on MITRE CWE →

Monitor CWE-644 Vulnerabilities

Get alerted when new CWE-644 CVEs affect your infrastructure.

Start Monitoring Free