EIP-2026-118983
PRE-CVEOmniHTTPd 1.1/2.0.x/2.4 - Sample Application URL Encoded Newline HTML Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118983. PoCs published by Matthew Murphy.
AI-analyzed exploit summary The exploit demonstrates an HTML injection vulnerability in OmniHTTPD's 'redir.exe' CGI script. By URL-encoding newline characters (%0D%0A) and injecting malicious HTML/JS, an attacker can trigger a 302 redirect response containing arbitrary script code.
Description
OmniHTTPd 1.1/2.0.x/2.4 - Sample Application URL Encoded Newline HTML Injection
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Matthew Murphy · textremotewindows
https://www.exploit-db.com/exploits/21757
The exploit demonstrates an HTML injection vulnerability in OmniHTTPD's 'redir.exe' CGI script. By URL-encoding newline characters (%0D%0A) and injecting malicious HTML/JS, an attacker can trigger a 302 redirect response containing arbitrary script code.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
OmniHTTPD (version not specified)
No auth needed
Prerequisites:
OmniHTTPD with the vulnerable 'redir.exe' CGI script enabled
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026