[20260801] - Core - Response header injection in download views
Joomla fixes CVE-2026-71572, response header injection in download views enabling reflected file download attacks, in 5.4.8/6.1.3.
Joomla disclosed a response header injection flaw (CVE-2026-71572) in multiple download views, caused by lack of output processing, enabling reflected file download and content-type confusion. It is rated low impact, severity, and probability and affects Joomla CMS 3.0.0-5.4.7 and 6.0.0-6.1.2. The fix ships in Joomla 5.4.8 and 6.1.3 on 2026-08-18.
- CVE-2026-71572 enables response header injection in Joomla download views
- Leads to reflected file download and content-type confusion
- Affects Joomla CMS 3.0.0-5.4.7 and 6.0.0-6.1.2
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-71572 | Response Header Injection in Joomla! Core Download Views (Reflected File Download) CVE-2026-71572 is a response header injection (CWE-93, CRLF injection) in the download views of Joomla! core, caused by a lack of output processing of values written into HTTP response headers. An attacker who can influence header content and persuade a high-privileged user to trigger a download (the CVSS 4.0 vector requires high privileges and user interaction) can inject CRLF sequences, producing content-type confusion or a reflected file download in the victim's browser. The impact is limited to the integrity of the response delivered to the user (low impact on the subsequent system in CVSS 4.0); there is no confidentiality or availability impact on the server itself. All Joomla! sites running core versions 3.0.0-5.4.7 or 6.0.0-6.1.2 are affected. No public proof of concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days. Do: Upgrade Joomla! core to a release newer than 5.4.7 on the 5.x line or newer than 6.1.2 on the 6.x line, per the Joomla 20260801 core advisory, and verify the installed version in the admin panel afterwards. Because exploitation requires a high-privilege account and user interaction, also review administrator accounts for signs of compromise and limit admin access. No public PoC or in-the-wild exploitation is known, so treat this as a routine medium-priority patch. | 4.8 | <1% |
| massmillions of Joomla! sites (affected ranges span essentially the entire current 3.x-6.x installed base) |
Project: Joomla! SubProject: CMS Impact: Low Severity: Low Probability: Low Versions: 3.0.0-5.4.7, 6.0.0-6.1.2 Exploit type: Response header injection Reported Date: 2026-07-02 Fixed Date: 2026-08-18 CVE Number: CVE-2026-71572 Description Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion. Affected Installs Joomla! CMS versions 3.0.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: arib06
This source does not provide full text. Read it at developer.joomla.org.