All versions of the package ithewei/libhv are vulnerable to HTTP Response Splitting when untrusted user input is used to build headers values. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content, like for example additional headers or new response body, leading to a potential XSS vulnerability.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2023-09-29T05:00:04.105Z

Updated: 2023-09-29T05:00:04.105Z

Reserved: 2023-02-20T10:28:48.929Z


Link: CVE-2023-26147

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-09-29T05:15:46.630

Modified: 2023-11-07T04:09:28.360


Link: CVE-2023-26147

JSON object: View

cve-icon Redhat Information

No data.