Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-644'

View all threats tagged with 'cwe-644'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-644

Threats Tagged 'cwe-644'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-66778: CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax in SAP_SE SAP Business AI Platform (Approuter)CVE-2026-66778
0

CVE-2026-66778 is a medium severity vulnerability in SAP Business AI Platform (Approuter) where certain HTTP request headers are not properly sanitized before being forwarded. This flaw allows an unauthenticated attacker to send crafted requests that could lead to limited unauthorized information disclosure. There is no impact on data integrity or system availability.

Join the discussion
CVE-2026-72574: CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax in picocms PicoCVE-2026-72574
0

A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control the origin of JavaScript and CSS assets loaded by the default theme. When base_url is unset (the default), Pico::getBaseUrl in lib/Pico.php builds the base URL from unvalidated Host, X-Forwarded-Host, X-Forwarded-Proto, and X-Forwarded-Port request headers.

Join the discussion
CVE-2026-0516: CWE-644 Improper neutralization of HTTP headers for scripting syntax in SonicWall SonicOSCVE-2026-0516
0

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

Join the discussion
CVE-2026-48061: CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax in litestar-org litestarCVE-2026-48061
0

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.

Join the discussion
CVE-2026-21762: CWE-644: Improper Neutralization of HTTP Headers for Scripting Syntax in HCLSoftware DevOps LoopCVE-2026-21762
0

HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attacks such as clickjacking, MIME-type sniffing, and cross-site scripting.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cwe-644
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses