Threats Tagged 'cwe-644'
View all threats tagged with 'cwe-644'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-644'
Click on any threat for detailed analysis and mitigation recommendations
0 Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An unauthenticated attacker can rotate either header to create a new bucket for each request, bypassing rootRateLimiter, badAuthRateLimiter, getKey(), and the getKeyWithUid() fallback used by public endpoints. This permits repeated POST /users/forgotPasswordEmail and verificationEmail requests, mail bombing registered users, consuming Firebase or SMTP quota, evading brute-force protection, and enabling resource exhaustion. Exploitability of cf-connecting-ip depends on deployment topology, but x-forwarded-for and direct-to-origin paths remain affected when those values are not overwritten by a trusted proxy. No fixed version is available as of this review. Join the discussion | CVE Database V5 | 08/20/2026, 16:16:43 UTC Added: 08/20/2026, 16:38:18 UTC |
0 Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18. Join the discussion | CVE Database V5 | 08/11/2026, 15:56:09 UTC Added: 08/11/2026, 16:12:23 UTC |
0 SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability. Join the discussion | CVE Database V5 | 08/11/2026, 00:19:50 UTC Added: 08/11/2026, 00:42:07 UTC |
0 CVE-2026-72574 is a host header injection vulnerability in picocms/Pico versions prior to 2.1.5. It allows an unauthenticated remote attacker to manipulate the origin of JavaScript and CSS assets loaded by the default theme by exploiting how the base URL is constructed from unvalidated HTTP headers when base_url is unset. Join the discussion | CVE Database V5 | 08/10/2026, 10:40:57 UTC Added: 08/10/2026, 10:56:47 UTC |
0 CVE-2026-0516 is a medium severity vulnerability in SonicWall SonicOS involving improper neutralization of HTTP headers. This flaw allows a remote attacker to manipulate the Host header, potentially redirecting firewall management users to arbitrary web domains. No specific affected versions or patches have been disclosed yet. Join the discussion | CVE Database V5 | 08/05/2026, 11:50:03 UTC Added: 08/05/2026, 12:51:00 UTC |
0 Litestar versions prior to 2.22.0 contain a vulnerability in the AllowedHostsMiddleware where the X-Forwarded-Host header is trusted as a fallback when the Host header is missing. This allows an attacker to bypass allowed hosts validation by omitting the Host header and supplying a malicious X-Forwarded-Host header. The vulnerability enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. The issue is fixed in version 2.22.0. Join the discussion | CVE Database V5 | 08/03/2026, 20:47:34 UTC Added: 08/03/2026, 21:18:56 UTC |
0 HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting. Join the discussion | CVE Database V5 | 07/17/2026, 17:10:33 UTC Added: 07/18/2026, 11:08:38 UTC |
0 The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. Join the discussion | CVE Database V5 | 07/02/2026, 23:52:49 UTC Added: 07/03/2026, 00:21:39 UTC |
Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive trustedHosts configuration, an attacker can poison the Host or X-Forwarded-Host header to manipulate the application’s $baseUrl. This bypasses the endpoint’s internal URL validation, forcing the backend Guzzle client to fetch a malicious payload from an attacker-controlled server and reflect it to the client with a Content-Type: application/javascript header. The vulnerability manifests when assetManager.cacheSourcePaths is set to false. This issue has been fixed in versions 4.18.0 and 5.10.0. Join the discussion | CVE Database V5 | 07/01/2026, 23:13:58 UTC Added: 07/01/2026, 23:51:36 UTC |
0 IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. Join the discussion | CVE Database V5 | 06/22/2026, 14:33:55 UTC Added: 06/22/2026, 15:39:21 UTC |
Showing 1 to 10 of 29 results