CRLF Injection Vulnerability in TUBITAK Pardus Software
CVE-2026-5140

8.8HIGH

What is CVE-2026-5140?

A CRLF injection vulnerability exists in TUBITAK's Pardus software, which can be exploited to bypass authentication mechanisms. Attackers may manipulate CRLF sequences, leading to unauthorized access. The issue is present in versions up to 0.6.4 and those prior to 0.8.0, highlighting a critical security concern for users and organizations utilizing this software.

Affected Version(s)

Pardus Update <=0.6.4 < 0.8.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Çağrı ESER
.