Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-113 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 24 | 24 | 0 |
▂▄█▆▂
2026-04 1 · 2026-05 4 · 2026-06 10 · 2026-07 7 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-40175 | 4.8 | 77.8 | — | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| CVE-2026-42578 | 2.9 | 62.0 | — | Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| CVE-2026-50630 | 6.5 | 33.8 | — | Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection |
| CVE-2026-67289 | 9.3 | 31.3 | — | FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection |
| CVE-2026-38967 | 9.8 | 26.3 | — | — |
| CVE-2026-38978 | 5.3 | 23.2 | — | — |
| CVE-2026-50576 | 6.8 | 22.8 | — | ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests |
| CVE-2026-50269 | 2.7 | 22.8 | — | AIOHTTP: CRLF injection in multipart headers |
| CVE-2026-50188 | 6.9 | 21.6 | — | Kirby: Request header injection in `Http\Remote` |
| CVE-2025-62826 | 4.3 | 21.5 | — | — |
| CVE-2025-71381 | 6.9 | 20.5 | — | Hono - Vary Header Injection in CORS Middleware |
| CVE-2026-44214 | 5.3 | 20.2 | — | eventsource-encoder: SSE event injection via unsanitized event and id fields |
| CVE-2025-62675 | 4.3 | 19.0 | — | — |
| CVE-2026-43966 | 6.3 | 16.6 | — | HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 |
| CVE-2026-63771 | 6.0 | 15.8 | — | Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header |
| CVE-2026-66746 | 5.3 | 15.6 | — | Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection |
| CVE-2026-44489 | 5.3 | 13.8 | — | Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-P… |
| CVE-2026-9658 | 7.3 | 13.6 | — | Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block heade… |
| CVE-2026-66753 | 6.3 | 12.5 | — | tiny-http 0.12.0 HTTP Response Splitting via Header Injection |
| CVE-2026-47675 | 5.3 | 12.3 | — | Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection |