CVE-2026-66753

tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides due to insufficient validation in header parsing and serialization. Attackers can exploit this injection primitive to perform response splitting, cache poisoning, session fixation via Set-Cookie injection, security header override, and request smuggling against line-feed-tolerant backends.
Configurations

No configuration.

History

28 Jul 2026, 17:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 3.7

28 Jul 2026, 16:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 16:20

Updated : 2026-07-30 20:03


NVD link : CVE-2026-66753

Mitre link : CVE-2026-66753

CVE.ORG link : CVE-2026-66753


JSON object : View

Products Affected

No product.

CWE
CWE-113

Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')