PT-2023-20526 · Unknown · Ithewei/Libhv

Alessio Della Libera

·

Published

2023-09-28

·

Updated

2023-10-02

·

CVE-2023-26148

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ithewei/libhv versions all
Description The issue affects the ithewei/libhv package, where untrusted user input used to set request headers can lead to CRLF Injection. An attacker can inject additional headers into the request by adding carriage return line feeds (r ) characters.
Recommendations For all versions, consider restricting the use of untrusted user input in setting request headers until a patch is available. As a temporary workaround, validate and sanitize all user input to prevent the injection of malicious characters, such as r .

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26148

Affected Products

Ithewei/Libhv