PT-2026-96325 · Dancer2 · Dancer2
CVE-2026-93711
·
Published
2026-09-22
·
Updated
2026-09-30
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dancer2 versions prior to 2.2.0
Description
The
headers to array() function fails to strip Carriage Return (CR) and Line Feed (LF) characters from response header names. While the routine removes these characters from header values, names containing them are passed to the PSGI server intact. If the server does not validate these keys, the bytes following the CRLF are written to the wire as separate header lines. This allows an attacker who can control the data used to derive header names to inject their own headers and perform response splitting.Recommendations
Update to version 2.2.0 or later.
As a temporary mitigation, avoid deriving header names directly from user-controlled request data.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dancer2