PoC Archive PoC Archive

tag

Header-Injection

Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 web Patched
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7webCRITICAL 10Patched2026-08-16CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner) KEV RW EPSS 100%
CVE-2022-40684 network Unverified
CVE-2022-40684networkCRITICAL 9.8Unverified2026-07-31camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
CVE-2026-33453 web Unverified
CVE-2026-33453webCRITICAL 9.8Unverified2026-07-06MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
CVE-2026-42281 web Patched
CVE-2026-42281webCRITICAL 9.2Patched2026-07-05CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)
CVE-2026-34975 web Patched
CVE-2026-34975webHIGH 8.5Patched2026-07-05Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
CVE-2026-33453 web Patched
CVE-2026-33453webCRITICAL 10Patched2026-07-05Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
CVE-2026-31908 web Patched
CVE-2026-31908webCRITICAL 10Patched2026-07-05Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927) EPSS 99%
CVE-2025-29927 web Patched
CVE-2025-29927webCRITICAL 9.1Patched2026-05-15