CVE detail
CVE-2019-16771 — CVE-2019-16771
Published 2019-12-06 · Modified 2026-06-17 · Vendor linecorp · Product armeria · Source nvd
MEDIUM
severity
CVSS-derived band
0.0098
EPSS probability
exploitation probability, 30d
59.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has been patched in 0.97.0. Potential impacts of this vulnerability include cross-user defacement, cache poisoning, Cross-site scripting (XSS), and page hijacking.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References