NONE · 0

CVE-2026-50188

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), ...

Vulnerability Description

Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-50188?

CVE-2026-50188 is a documented vulnerability. Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), ...

How severe is CVE-2026-50188?

CVSS scoring is not yet available for CVE-2026-50188. Check NVD for updates.

Is there a patch for CVE-2026-50188?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.