boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-113

Weakness type CWE-113 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
24240

Monthly trend

▂▄█▆▂

2026-04 1 · 2026-05 4 · 2026-06 10 · 2026-07 7 · 2026-08 2

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-401754.877.8Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2026-425782.962.0Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-506306.533.8Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection
CVE-2026-672899.331.3FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
CVE-2026-389679.826.3
CVE-2026-389785.323.2
CVE-2026-505766.822.8ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests
CVE-2026-502692.722.8AIOHTTP: CRLF injection in multipart headers
CVE-2026-501886.921.6Kirby: Request header injection in `Http\Remote`
CVE-2025-628264.321.5
CVE-2025-713816.920.5Hono - Vary Header Injection in CORS Middleware
CVE-2026-442145.320.2eventsource-encoder: SSE event injection via unsanitized event and id fields
CVE-2025-626754.319.0
CVE-2026-439666.316.6HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2
CVE-2026-637716.015.8Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
CVE-2026-667465.315.6Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
CVE-2026-444895.313.8Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-P…
CVE-2026-96587.313.6Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block heade…
CVE-2026-667536.312.5tiny-http 0.12.0 HTTP Response Splitting via Header Injection
CVE-2026-476755.312.3Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
axios2
fortinet2
guzzle2
aio-libs1
apache1
elixir-tesla1
fbeta-gmbh1
freerdp1
getkirby1
github1
hono1
honojs1
netty1
ninenines1
rexxars1