Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-113
Weakness type CWE-113 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 37 | 37 | 0 |
Monthly trend
▂▄█▆▅▇▁
2026-04 1 · 2026-05 4 · 2026-06 10 · 2026-07 7 · 2026-08 6 · 2026-09 9 · 2026-10 0
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-40175 | 4.8 | 69.6 | — | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
| CVE-2026-42578 | 2.9 | 65.9 | — | Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation |
| CVE-2026-90819 | 6.9 | 49.9 | — | a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java B… |
| CVE-2026-50630 | 6.5 | 48.7 | — | Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection |
| CVE-2026-38967 | 9.8 | 46.8 | — | — |
| CVE-2026-75419 | 8.8 | 44.0 | — | — |
| CVE-2026-77360 | 6.3 | 43.6 | — | oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass |
| CVE-2026-50269 | 2.7 | 43.0 | — | AIOHTTP: CRLF injection in multipart headers |
| CVE-2026-50576 | 6.8 | 40.2 | — | ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests |
| CVE-2026-85077 | 8.2 | 39.6 | — | Sanic: HTTP response header injection via missing CR/LF validation in Sanic HTTP/1.1 re… |
| CVE-2026-39915 | 8.5 | 39.0 | — | TIM Flow < 26.0.6 CRLF Injection via rt Parameter |
| CVE-2026-77341 | 5.3 | 37.8 | — | cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response wr… |
| CVE-2026-94216 | 2.1 | 36.8 | — | ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize re… |
| CVE-2026-50188 | 6.9 | 36.3 | — | Kirby: Request header injection in `Http\Remote` |
| CVE-2026-43966 | 6.3 | 35.4 | — | HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 |
| CVE-2026-63771 | 6.0 | 35.0 | — | Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header |
| CVE-2026-67289 | 9.3 | 34.9 | — | FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection |
| CVE-2026-38978 | 5.3 | 31.7 | — | — |
| CVE-2026-93711 | 6.5 | 28.9 | — | Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header name… |
| CVE-2025-62826 | 4.3 | 28.8 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| axios | 2 |
| fortinet | 2 |
| guzzle | 2 |
| tornadoweb | 2 |
| a2aproject | 1 |
| aio-libs | 1 |
| apache | 1 |
| elixir-tesla | 1 |
| fbeta-gmbh | 1 |
| freerdp | 1 |
| getkirby | 1 |
| github | 1 |
| hono | 1 |
| honojs | 1 |
| http4s | 1 |