
  • CWE ID
  • 113
  • CWE Name
  • Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
  • CWE Abstraction
  • Variant
  • CWE structure
  • Simple
  • CWE Status
  • Incomplete
The software receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
Extended Description
Related CWEs
CWE ID View ID Nature Ordinal
93 1000 ChildOf Primary
79 1000 CanPrecede
20 700 ChildOf Primary
436 1000 ChildOf