CVE-2026-50188

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.

Scoring

Severity
MEDIUM
CVSS base score
6.9
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
EPSS probability
0.44%
CWE
CWE-93, CWE-113
Published
2026-07-09
Last modified
2026-07-10

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs