CVE-2020-1695

HIGH

Resteasy 3.0.0-3.11.9 and 4.0.0-4.5.9 - HTTP Response Header Injection via Improper Input Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-1695. PoCs published by dawetmaster, andikahilmy.

AI-analyzed exploit summary This repository contains test cases and code for RESTEasy, specifically focusing on CVE-2020-1695. It includes Arquillian tests and application code to demonstrate the vulnerability in a controlled environment.

Description

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.

Exploits (2)

nomisec WRITEUP
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2020-1695-Resteasy-vulnerable

This repository contains test cases and code for RESTEasy, specifically focusing on CVE-2020-1695. It includes Arquillian tests and application code to demonstrate the vulnerability in a controlled environment.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: RESTEasy (JBoss)
No auth needed
Prerequisites: Java environment · Maven · RESTEasy setup
devstral-2 · analyzed Mar 14, 2026 Full analysis →
nomisec WRITEUP
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2020-1695-Resteasy-vulnerable

This repository contains test cases and code for RESTEasy, specifically focusing on CVE-2020-1695. It includes Arquillian tests and application code to demonstrate the vulnerability in a controlled environment.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: RESTEasy (JBoss)
No auth needed
Prerequisites: Java environment · RESTEasy setup
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1695

Scores

CVSS v3 7.5
EPSS 0.0202
EPSS Percentile 78.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (4)
fedoraproject/fedora 32
fedoraproject/fedora 33
org.jboss.resteasy/resteasy-client 4.0.0 - 4.6.0Maven
redhat/resteasy 3.0.0 - 3.12.0
Published May 19, 2020
Tracked Since Feb 18, 2026