CVE-2026-1536 โ CRLF Injection in Redhat Enterprise Linux
Severity
5.3MEDIUMNVD
CNA5.8
EPSS
0.1%
top 69.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateFeb 8
Description
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages0 packages
Also affects: Enterprise Linux 10.0, 6.0, 7.0, 8.0, 9.0
๐ดVulnerability Details
4CVEListโถ
Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition headerโ2026-01-28