CVSS 3.1 Score 7.2 of 10 (high)


Published Jul 6, 2023
Updated: Nov 7, 2023
CWE ID 444
CWE ID 113


CVE-2023-26137 is a vulnerability that affects all versions of the package drogonframework/drogon. This vulnerability is related to HTTP Response Splitting and occurs when untrusted user input is used to build header values in the addHeader and addCookie functions. Attackers can exploit this vulnerability by injecting malicious content using the \r\n (carriage return line feeds) characters to end the HTTP response headers. The vulnerability has a high severity rating with a base score of 7.2, indicating the potential danger it poses to organizations. To remediate this vulnerability, users should update their drogon packages to the latest version available.


Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-26137 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options