Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-644 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 12 | 12 | 0 |
▂▅▅█
2026-05 1 · 2026-06 3 · 2026-07 3 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48126 | 8.2 | 26.5 | — | Algernon: Host header path traversal in --domain mode reads files and runs Lua from par… |
| CVE-2026-55791 | 6.9 | 26.1 | — | Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in a… |
| CVE-2026-10836 | 5.1 | 23.5 | — | Improper neutralization of HTTP headers in Password Manager |
| CVE-2026-48061 | 5.9 | 20.8 | — | Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwa… |
| CVE-2026-54477 | 5.1 | 19.4 | — | Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax |
| CVE-2026-72574 | 6.1 | 15.5 | — | picocms Pico - Host Header Injection Enables Script Source Hijacking |
| CVE-2026-66778 | 5.3 | 14.6 | — | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-0516 | 6.5 | 10.8 | — | — |
| CVE-2024-51454 | 6.1 | 8.0 | — | IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by v… |
| CVE-2026-21762 | 5.3 | 7.0 | — | Missing HTTP Security Headers in DevOps Loop |
| CVE-2026-4096 | 6.1 | 4.6 | — | A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Inject… |
| CVE-2026-67179 | 7.8 | 3.6 | — | Genkit improper host header validation |
| Vendor | CVEs |
|---|---|
| ibm | 2 |
| craftcms | 1 |
| gardyn | 1 |
| genkit-ai | 1 |
| hclsoftware | 1 |
| litestar-org | 1 |
| password manager | 1 |
| picocms | 1 |
| sap_se | 1 |
| sonicwall | 1 |
| xyproto | 1 |