Fallos del tipo CWE-644

64 resultados

Neutralização inadequada de cabeçalhos HTTP para sintaxe de script

Ocorre quando a aplicação falha em sanitizar ou validar cabeçalhos HTTP antes de usá-los em contextos onde código pode ser executado (como JavaScript, CSS ou templates). Um atacante injeta sintaxe maliciosa no cabeçalho (ex: User-Agent, Referer) e a aplicação a reflete sem proteção, permitindo execução de script no navegador da vítima (XSS).

Ejemplo

Uma página de erro que exibe 'Você veio de: [Referer]' sem escapar o valor. Um atacante envia Referer: javascript:alert('roubado'), e quando a página é renderizada, o script executa no contexto do site legítimo.

Cómo mitigar

Sempre escape ou sanitize cabeçalhos HTTP antes de inseri-los em HTML, atributos ou contextos de script — use funções nativas do framework (htmlspecialchars, textContent, etc.). Valide e rejeite cabeçalhos com padrões suspeitos em entrada, não apenas na saída.

CVE-2024-51454MEDIUMIBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observedEPSS 0.3%CVE-2025-24339MEDIUMA vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the EPSS 0.3%CVE-2025-23191LOWCache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERPEPSS 0.2%CVE-2025-27632MEDIUMA Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request EPSS 0.2%CVE-2026-72574MEDIUMpicocms Pico - Host Header Injection Enables Script Source HijackingEPSS 0.2%CVE-2025-67724MEDIUMTornado vulnerable to Header Injection and XSS via reason argumentEPSS 0.2%CVE-2026-66778MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.2%CVE-2023-35894MEDIUMIBM Control Center HOST header injectionEPSS 0.2%CVE-2022-43847MEDIUMIBM Aspera Console HTTP header injectionEPSS 0.2%CVE-2024-51451MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2025-14807MEDIUMIBM InfoSphere Information Server is vulnerable to HTTP header injectionEPSS 0.2%CVE-2025-40631LOWHTTP host header injection vulnerability in IceWarp Mail ServerEPSS 0.2%CVE-2025-36227MEDIUMMultiple vulnerabilities in IBM Aspera FaspexEPSS 0.2%CVE-2026-1698MEDIUMHTTP Host header vulnerability in WebClient and WebScheduler web appsEPSS 0.2%CVE-2026-0516MEDIUMA improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the HostEPSS 0.2%CVE-2025-66485MEDIUMMultiple vulnerabilities have been addressed in IBM Aspera SharesEPSS 0.2%CVE-2025-52647MEDIUMHCL BigFix WebUI is affected by a host header poisoning vulnerabilityEPSS 0.2%CVE-2024-40686MEDIUMIBM SmartCloud Analytics - Log Analysis HOST header injectionEPSS 0.2%CVE-2025-27901MEDIUMMultiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and WindowsEPSS 0.2%CVE-2026-21762LOWMissing HTTP Security Headers in DevOps LoopEPSS 0.2%