CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename.
CVE-2016-1900
UNRATEDCVSS · not yet scored
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
- No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: Not assessed
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
- CVSS v3
- —
- EchelonGraph score
- Not yet assessedEchelonGraph has no severity assessment for this CVE yet. This is not a rating of zero.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
Published
January 20, 2016
Last Modified
June 17, 2026
References (20)
- cve@mitrehttp://git.zx2c4.com/cgit/commit/?id=513b3863d999f91b47d7e9f26710390db55f9463
- cve@mitrehttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/176167.html
- cve@mitrehttp://lists.fedoraproject.org/pipermail/package-announce/2016-January/176198.html
- cve@mitrehttp://lists.opensuse.org/opensuse-updates/2016-01/msg00067.html
- cve@mitrehttp://lists.opensuse.org/opensuse-updates/2016-01/msg00084.html
- cve@mitrehttp://lists.zx2c4.com/pipermail/cgit/2016-January/002790.html
- cve@mitrehttp://lists.zx2c4.com/pipermail/cgit/2016-January/002817.html
- cve@mitrehttp://www.debian.org/security/2016/dsa-3545
- cve@mitrehttp://www.openwall.com/lists/oss-security/2016/01/14/3
- cve@mitrehttp://www.openwall.com/lists/oss-security/2016/01/14/6
- af854a3a-2127-422b-91ae-364da2661108http://git.zx2c4.com/cgit/commit/?id=513b3863d999f91b47d7e9f26710390db55f9463
- af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176167.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.fedoraproject.org/pipermail/package-announce/2016-January/176198.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.opensuse.org/opensuse-updates/2016-01/msg00067.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.opensuse.org/opensuse-updates/2016-01/msg00084.html
Vendor Advisories for CVE-2016-1900
Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.
Related CVEs(same product)· as of October 4, 2026
Same product
3 shownDebian:11:cgit
Frequently asked(3)
What is CVE-2016-1900?
CVE-2016-1900 is a publicly disclosed vulnerability published on January 20, 2016. CRLF injection vulnerability in the cgitprinthttp_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline…
When was CVE-2016-1900 disclosed?
CVE-2016-1900 was first published on January 20, 2016, with the most recent update on June 17, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
How do I remediate CVE-2016-1900?
No fix for CVE-2016-1900 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix.
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2016-1900
Is Your Infrastructure Affected by CVE-2016-1900?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.