ZeroHour

CVE-2023-26137

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p37
Published
()
Modified
Description

All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values in the addHeader and addCookie functions. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.

Vendors
drogon
Products
drogon
Weakness
CWE-113, CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.