CWE-113

CWE-113 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-113, highest CVSS first.

  1. HIGH 8.2CVE-2026-85077public PoC

    Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names and values without rejecting carriage-return or line-feed character…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-93711public PoC

    Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from each header value but not from the name. A name carrying them therefore reaches the PSGI server intact. A server t…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-77360public PoC

    oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in packages/server/src/plugins/cors.ts copies a client's incoming Vary request header into the response instead o…

    AI risk analysis on Exploit-DB.ai →