CVE-2016-1900

UNRATEDCVSS · not yet scored
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: Not assessed

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename.

CVSS v3
—
EchelonGraph score
Not yet assessedEchelonGraph has no severity assessment for this CVE yet. This is not a rating of zero.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

January 20, 2016

Last Modified

June 17, 2026

Vendor Advisories for CVE-2016-1900

Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.

Frequently asked(3)

What is CVE-2016-1900?
CVE-2016-1900 is a publicly disclosed vulnerability published on January 20, 2016. CRLF injection vulnerability in the cgitprinthttp_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline…
When was CVE-2016-1900 disclosed?
CVE-2016-1900 was first published on January 20, 2016, with the most recent update on June 17, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
How do I remediate CVE-2016-1900?
No fix for CVE-2016-1900 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2016-1900

Explore →

Is Your Infrastructure Affected by CVE-2016-1900?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.