CVE-2023-26138: CRLF Injection
All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \r\n (carriage return line feeds) characters and inject additional headers in the request sent.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26138?
CVE-2023-26138 is a vulnerability in all versions of the package drogonframework/drogon that allows for CRLF Injection when untrusted user input is used to set request headers in the addHeader function.
How does the CVE-2023-26138 vulnerability occur?
The CVE-2023-26138 vulnerability occurs when an attacker adds the \r\n characters to inject additional headers in the request sent.
What is the severity of CVE-2023-26138?
CVE-2023-26138 has a severity rating of medium with a value of 4.3.
What software is affected by CVE-2023-26138?
All versions of the Drogon framework (drogonframework/drogon) are affected by CVE-2023-26138.
How can I fix CVE-2023-26138?
To fix CVE-2023-26138, it is recommended to update to a version of the Drogon framework that contains a patch for the CRLF Injection vulnerability.