SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-113 HTTP Response Splitting

Coverage: 23 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 23 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged untrusted input being used in HTTP headers or redirect locations without proper sanitization. Attackers can inject CRLF sequences (\r\n) and potentially add/modify headers.

Why it matters

Attackers can inject CRLF sequences to split responses or set malicious headers.

Safer examples

1) Never put raw user input into headers

Use server-generated values or allowlists.

2) Validate and sanitize header values

Reject values containing \r or \n and enforce allowed character sets.

3) Use framework helpers

Framework response APIs often normalize headers safely; avoid manual header concatenation.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.