Description
Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A successful exploit could result in the generation of manipulated links or responses, potentially leading to limited information disclosure or compromising the integrity of dependent services.
Problem types
CWE-644 Improper neutralization of HTTP headers for scripting syntax
Product status
Any version before 08/07/2025
08/07/2025 (date)
References
www.incibe.es/...o/multiple-vulnerabilities-password-manager