CVE-2026-54214: TeamDavid: Header Injection through the 'cType' URL parameter
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid through Rollout 524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54214?
The severity of CVE-2026-54214 is rated at risk level 37.
How do I fix CVE-2026-54214?
To fix CVE-2026-54214, update the TeamDavid Webbox application to the latest version that addresses this header injection vulnerability.
What impact does CVE-2026-54214 have on my application?
CVE-2026-54214 allows attackers to perform HTTP header injection, potentially leading to content spoofing or manipulation of HTTP responses.
Is CVE-2026-54214 a high-risk vulnerability?
Given its risk level of 37, CVE-2026-54214 poses a significant threat and should be addressed urgently.
Who is affected by CVE-2026-54214?
Users of the TeamDavid Webbox application are affected by CVE-2026-54214 due to its improper handling of the 'cType' URL parameter.