VulnerabilityModified
CVE-2023-26148
All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers.
MEDIUM 5.3EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-93, CWE-74
- Affected
- ithewei/libhv
- Source
- report@snyk.io
References
- https://gist.github.com/dellalibera/65d136066fdd5ea4dddaadaa9b0ba90eExploit, Third Party Advisory
- https://security.snyk.io/vuln/SNYK-UNMANAGED-ITHEWEILIBHV-5730769Third Party Advisory
- https://gist.github.com/dellalibera/65d136066fdd5ea4dddaadaa9b0ba90eExploit, Third Party Advisory
- https://security.snyk.io/vuln/SNYK-UNMANAGED-ITHEWEILIBHV-5730769Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.