CVE-2023-26148

MEDIUM

ithewei libhv - CRLF Injection via Request Header Manipulation

Title source: llm
STIX 2.1

Description

All versions of the package ithewei/libhv are vulnerable to CRLF Injection when untrusted user input is used to set request headers. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0038
EPSS Percentile 29.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-93 CWE-74
Status published
Products (1)
ithewei/libhv
Published Sep 29, 2023
Tracked Since Feb 18, 2026