{"id":"CVE-2016-9964","aliases":["GHSA-j6f7-hghw-g437","PYSEC-2016-24"],"url":"https://o3.security/vulnerability/CVE-2016-9964","summary":"bottle.py vulnerable to CRLF Injection","details":"redirect() in bottle.py in bottle 0.12.10 doesn't filter a \"\\r\\n\" sequence, which leads to a CRLF attack, as demonstrated by a redirect(\"233\\r\\nSet-Cookie: name=salt\") call.","published":"2016-12-16T09:59:00.373Z","modified":"2026-07-08T05:49:20.548414414Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"bottle","fixedVersion":"0.12.11"}],"fix":{"url":"https://github.com/bottlepy/bottle/commit/6d7e13da0f998820800ecb3fe9ccee4189aefb54","label":"bottlepy/bottle@6d7e13d"},"references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2016/dsa-3743"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/94961"},{"type":"FIX","url":"https://github.com/bottlepy/bottle/commit/6d7e13da0f998820800ecb3fe9ccee4189aefb54"},{"type":"FIX","url":"https://github.com/bottlepy/bottle/issues/913"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:49:20.548414414Z"}}