CRLF Injection Vulnerability in Drogon Framework
CVE-2023-26138
5.4MEDIUM
What is CVE-2023-26138?
All versions of the Drogon Framework are susceptible to CRLF Injection vulnerabilities. This occurs when untrusted user input is used to set request headers within the addHeader function. An attacker can exploit this flaw by injecting carriage return and line feed characters ( ) into the request, allowing them to add unauthorized headers to the HTTP requests. This could lead to further exploits, such as session hijacking or response splitting.
Affected Version(s)
drogonframework/drogon 0
