Skip to main content

Threats Tagged 'cwe-644'

View all threats tagged with 'cwe-644'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-644

Threats Tagged 'cwe-644'

Click on any threat for detailed analysis and mitigation recommendations

Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An unauthenticated attacker can rotate either header to create a new bucket for each request, bypassing rootRateLimiter, badAuthRateLimiter, getKey(), and the getKeyWithUid() fallback used by public endpoints. This permits repeated POST /users/forgotPasswordEmail and verificationEmail requests, mail bombing registered users, consuming Firebase or SMTP quota, evading brute-force protection, and enabling resource exhaustion. Exploitability of cf-connecting-ip depends on deployment topology, but x-forwarded-for and direct-to-origin paths remain affected when those values are not overwritten by a trusted proxy. No fixed version is available as of this review.

Join the discussion

Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.

Join the discussion

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.

Join the discussion

CVE-2026-72574 is a host header injection vulnerability in picocms/Pico versions prior to 2.1.5. It allows an unauthenticated remote attacker to manipulate the origin of JavaScript and CSS assets loaded by the default theme by exploiting how the base URL is constructed from unvalidated HTTP headers when base_url is unset.

Join the discussion

CVE-2026-0516 is a medium severity vulnerability in SonicWall SonicOS involving improper neutralization of HTTP headers. This flaw allows a remote attacker to manipulate the Host header, potentially redirecting firewall management users to arbitrary web domains. No specific affected versions or patches have been disclosed yet.

Join the discussion

Litestar versions prior to 2.22.0 contain a vulnerability in the AllowedHostsMiddleware where the X-Forwarded-Host header is trusted as a fallback when the Host header is missing. This allows an attacker to bypass allowed hosts validation by omitting the Host header and supplying a malicious X-Forwarded-Host header. The vulnerability enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. The issue is fixed in version 2.22.0.

Join the discussion

HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.

Join the discussion
0

The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.

Join the discussion

Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive trustedHosts configuration, an attacker can poison the Host or X-Forwarded-Host header to manipulate the application’s $baseUrl. This bypasses the endpoint’s internal URL validation, forcing the backend Guzzle client to fetch a malicious payload from an attacker-controlled server and reflect it to the client with a Content-Type: application/javascript header. The vulnerability manifests when assetManager.cacheSourcePaths is set to false. This issue has been fixed in versions 4.18.0 and 5.10.0.

Join the discussion

IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

Join the discussion

Showing 1 to 10 of 29 results

Filters:Tag: cwe-644
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses