CVE-2026-3234

A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeenc() function, allows a remote attacker to bypass input validation. By injecting CRLF sequences into the cluster configuration, an attacker can corrupt the response body of INFO endpoint responses. Exploitation requires network access to the MCMP protocol port, but no authentication is needed.
Configurations

No configuration.

History

17 Jun 2026, 10:43

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en mod_proxy_cluster. Esta vulnerabilidad, una inyección de Retorno de Carro y Salto de Línea (CRLF) en la función decodeenc(), permite a un atacante remoto eludir la validación de entrada. Al inyectar secuencias CRLF en la configuración del clúster, un atacante puede corromper el cuerpo de la respuesta de las respuestas del endpoint INFO. La explotación requiere acceso de red al puerto del protocolo MCMP, pero no se necesita autenticación.

12 Mar 2026, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 11:15

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3234

Mitre link : CVE-2026-3234

CVE.ORG link : CVE-2026-3234


JSON object : View

Products Affected

No product.

CWE
CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')