{"id":"CVE-2026-50188","aliases":["GHSA-4v4h-m2qq-ppgw"],"url":"https://o3.security/vulnerability/CVE-2026-50188","summary":"Kirby: Request header injection in `Http\\Remote`","details":"Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.","published":"2026-07-09T18:44:56.901Z","modified":"2026-08-12T03:51:48.480733132Z","cvss":null,"epss":{"score":0.00443,"percentile":0.37178,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getkirby/cms","fixedVersion":"4.9.4"},{"ecosystem":"Packagist","name":"getkirby/cms","fixedVersion":"5.4.4"}],"fix":{"url":"https://github.com/getkirby/kirby/commit/aa33414e1669e866cdd6f4decfae2a669e8bb828","label":"getkirby/kirby@aa33414"},"references":[{"type":"WEB","url":"https://github.com/getkirby/kirby/releases/tag/4.9.4"},{"type":"WEB","url":"https://github.com/getkirby/kirby/releases/tag/5.4.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50188.json"},{"type":"ADVISORY","url":"https://github.com/getkirby/kirby/security/advisories/GHSA-4v4h-m2qq-ppgw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50188"},{"type":"FIX","url":"https://github.com/getkirby/kirby/commit/aa33414e1669e866cdd6f4decfae2a669e8bb828"},{"type":"FIX","url":"https://github.com/getkirby/kirby/commit/fad9cbd22c73ed0fbd3aaf62310a8dcacfc007cd"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.480733132Z"}}