GHSA-7wc8-wvc4-m498
LOWCVE-2026-42874The Response.setcookie() method does not sanitize its string arguments, and in particular will not detect the presence of the \r\n sequence in them. This can be a potential source of header injection attacks.
- Affected
- < 2.6.1
- Fixed in
- 2.6.1
- Weakness
- CWE-113
- Published
- 2026-05-05
- Source
- github