PT-2026-96325 · Dancer2 · Dancer2

CVE-2026-93711

·

Published

2026-09-22

·

Updated

2026-09-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dancer2 versions prior to 2.2.0
Description The headers to array() function fails to strip Carriage Return (CR) and Line Feed (LF) characters from response header names. While the routine removes these characters from header values, names containing them are passed to the PSGI server intact. If the server does not validate these keys, the bytes following the CRLF are written to the wire as separate header lines. This allows an attacker who can control the data used to derive header names to inject their own headers and perform response splitting.
Recommendations Update to version 2.2.0 or later. As a temporary mitigation, avoid deriving header names directly from user-controlled request data.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93711

Affected Products

Dancer2