Weaknesses of type CWE-644

64 results

Neutralização inadequada de headers HTTP para sintaxe de script

A aplicação falha em sanitizar headers HTTP antes de usá-los em contextos onde código ou script pode ser interpretado, permitindo que um atacante injete comandos maliciosos. Isso ocorre quando dados do header (como User-Agent, Referer ou headers customizados) são refletidos em respostas sem validação, criando vetor para XSS ou injeção de código.

Example

Um servidor reflete o header 'X-Forwarded-For' diretamente em uma página de erro sem escapar caracteres especiais. Um atacante envia 'X-Forwarded-For: <script>alert(1)</script>' e o navegador executa o script, roubando sessão do usuário legítimo que visita a página.

How to mitigate

Valide e sanitize todos os headers HTTP antes de usá-los em respostas HTML ou contextos de execução. Use encodificação apropriada (HTML entity encoding para HTML, URL encoding para URLs) e implemente Content Security Policy (CSP) para limitar execução de scripts inline. Aplique whitelist rigorosa para headers esperados.

CVE-2024-51454MEDIUMIBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observedEPSS 0.3%CVE-2025-24339MEDIUMA vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the EPSS 0.3%CVE-2025-23191LOWCache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERPEPSS 0.2%CVE-2025-27632MEDIUMA Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request EPSS 0.2%CVE-2026-72574MEDIUMpicocms Pico - Host Header Injection Enables Script Source HijackingEPSS 0.2%CVE-2025-67724MEDIUMTornado vulnerable to Header Injection and XSS via reason argumentEPSS 0.2%CVE-2026-66778MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.2%CVE-2023-35894MEDIUMIBM Control Center HOST header injectionEPSS 0.2%CVE-2022-43847MEDIUMIBM Aspera Console HTTP header injectionEPSS 0.2%CVE-2024-51451MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2025-14807MEDIUMIBM InfoSphere Information Server is vulnerable to HTTP header injectionEPSS 0.2%CVE-2025-40631LOWHTTP host header injection vulnerability in IceWarp Mail ServerEPSS 0.2%CVE-2025-36227MEDIUMMultiple vulnerabilities in IBM Aspera FaspexEPSS 0.2%CVE-2026-1698MEDIUMHTTP Host header vulnerability in WebClient and WebScheduler web appsEPSS 0.2%CVE-2026-0516MEDIUMA improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the HostEPSS 0.2%CVE-2025-66485MEDIUMMultiple vulnerabilities have been addressed in IBM Aspera SharesEPSS 0.2%CVE-2025-52647MEDIUMHCL BigFix WebUI is affected by a host header poisoning vulnerabilityEPSS 0.2%CVE-2024-40686MEDIUMIBM SmartCloud Analytics - Log Analysis HOST header injectionEPSS 0.2%CVE-2025-27901MEDIUMMultiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and WindowsEPSS 0.2%CVE-2026-21762LOWMissing HTTP Security Headers in DevOps LoopEPSS 0.2%