CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.
Loading...
Loading...
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the came_from parameter to _admin/login.
October 29, 2015
May 6, 2026
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| kallithea | 0.0 ... 0.2.99-pre (7 versions) | 0.3 | — |
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Kallithea 0.2.9 - 'came_from' HTTP Response Splitting
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2015-5285
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.