Rust tiny http: tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A)… (CVE-2026-66753)
Rust tiny-http versions up to 0.12.0 contain an HTTP header injection vulnerability that permits attackers to inject carriage return and line feed characters into HTTP header values. This flaw arises from insufficient validation during header parsing and serialization on both request and response sides. Exploitation can lead to response splitting, cache poisoning, session fixation via Set-Cookie injection, security header override, and request smuggling against backends tolerant to line feeds. The vulnerability is tracked as CVE-2026-66753 and has a medium severity rating with a CVSS score of 3.7. No official patch or fix information is currently provided.
AI Analysis
Technical Summary
The vulnerability in rust-tiny-http (<=0.12.0) allows injection of CR (0x0D) and LF (0x0A) bytes into HTTP header values due to inadequate validation in header parsing and serialization. This enables attackers to perform HTTP response splitting, cache poisoning, session fixation through Set-Cookie header manipulation, override security headers, and conduct request smuggling attacks on line-feed-tolerant backend systems. The issue is categorized under CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers). There is no vendor advisory or patch information available to confirm remediation status.
Potential Impact
Successful exploitation can lead to HTTP response splitting, cache poisoning, session fixation, security header override, and request smuggling attacks. These impacts can compromise web application behavior and security controls relying on HTTP headers. The CVSS score of 3.7 indicates a moderate impact primarily affecting integrity, with no direct confidentiality or availability impact reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider mitigating risks by validating and sanitizing HTTP header inputs at application or proxy layers if feasible. Monitor vendor channels for updates regarding an official fix.
Rust tiny http: tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A)… (CVE-2026-66753)
Description
Rust tiny-http versions up to 0.12.0 contain an HTTP header injection vulnerability that permits attackers to inject carriage return and line feed characters into HTTP header values. This flaw arises from insufficient validation during header parsing and serialization on both request and response sides. Exploitation can lead to response splitting, cache poisoning, session fixation via Set-Cookie injection, security header override, and request smuggling against backends tolerant to line feeds. The vulnerability is tracked as CVE-2026-66753 and has a medium severity rating with a CVSS score of 3.7. No official patch or fix information is currently provided.
CVSS v3.1
Score 3.7low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in rust-tiny-http (<=0.12.0) allows injection of CR (0x0D) and LF (0x0A) bytes into HTTP header values due to inadequate validation in header parsing and serialization. This enables attackers to perform HTTP response splitting, cache poisoning, session fixation through Set-Cookie header manipulation, override security headers, and conduct request smuggling attacks on line-feed-tolerant backend systems. The issue is categorized under CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers). There is no vendor advisory or patch information available to confirm remediation status.
Potential Impact
Successful exploitation can lead to HTTP response splitting, cache poisoning, session fixation, security header override, and request smuggling attacks. These impacts can compromise web application behavior and security controls relying on HTTP headers. The CVSS score of 3.7 indicates a moderate impact primarily affecting integrity, with no direct confidentiality or availability impact reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider mitigating risks by validating and sanitizing HTTP header inputs at application or proxy layers if feasible. Monitor vendor channels for updates regarding an official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5wm6-g4fr-88x8
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-66753"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a6941dd9c2644c7f86c14d7
Added to database: 07/28/2026, 23:57:17 UTC
Last enriched: 08/07/2026, 03:36:19 UTC
Last updated: 09/12/2026, 10:01:32 UTC
Views: 43
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.