Common Weakness Enumeration
CWE Definition / CWE-113
CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
Published:19 Jul 2006
Organization:MITRE
Modified:11 Dec 2025
