CVE-2026-54199: TeamDavid: Header Injection through request body in link storing functionality
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClientcelink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link, resulting in the ability to control the response headers. This issue affects TeamDavid through Rollout 524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54199?
The severity of CVE-2026-54199 is rated at 36, indicating a moderate risk level.
How do I fix CVE-2026-54199?
To fix CVE-2026-54199, it is essential to implement proper input validation to prevent HTTP header injection.
What functionality in TeamDavid is affected by CVE-2026-54199?
CVE-2026-54199 affects the link storing functionality in TeamDavid's Webbox application.
What is the impact of CVE-2026-54199?
The impact of CVE-2026-54199 includes the potential for HTTP header injection, which can lead to security vulnerabilities.
When was CVE-2026-54199 published?
CVE-2026-54199 was published on August 7, 2026.