boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-113

Weakness type CWE-113 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals

Totals
CVEs all-timeCVEs YTDKEV all-time
37370

Monthly trend

▂▄█▆▅▇▁

2026-04 1 · 2026-05 4 · 2026-06 10 · 2026-07 7 · 2026-08 6 · 2026-09 9 · 2026-10 0

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-401754.869.6—Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-425782.965.9—Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-908196.949.9—a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java B…
CVE-2026-506306.548.7—Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection
CVE-2026-389679.846.8——
CVE-2026-754198.844.0——
CVE-2026-773606.343.6—oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
CVE-2026-502692.743.0—AIOHTTP: CRLF injection in multipart headers
CVE-2026-505766.840.2—ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests
CVE-2026-850778.239.6—Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 re…
CVE-2026-399158.539.0—TIM Flow < 26.0.6 CRLF Injection via rt Parameter
CVE-2026-773415.337.8—cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response wr…
CVE-2026-942162.136.8—ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize re…
CVE-2026-501886.936.3—Kirby: Request header injection in `Http\Remote`
CVE-2026-439666.335.4—HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
CVE-2026-637716.035.0—Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
CVE-2026-672899.334.9—FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
CVE-2026-389785.331.7——
CVE-2026-937116.528.9—Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header name…
CVE-2025-628264.328.8——

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
axios2
fortinet2
guzzle2
tornadoweb2
a2aproject1
aio-libs1
apache1
elixir-tesla1
fbeta-gmbh1
freerdp1
getkirby1
github1
hono1
honojs1
http4s1