Medium severity6.5NVD Advisory· Published Mar 12, 2020· Updated Jun 17, 2026
CVE-2020-6858
CVE-2020-6858
Description
Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.hotels.styx:styx-apiMaven | < 1.0.0-rc1 | 1.0.0-rc1 |
Affected products
11cpe:2.3:a:hotels:styx:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:hotels:styx:*:*:*:*:*:*:*:*range: <=0.7.10
- cpe:2.3:a:hotels:styx:1.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:hotels:styx:1.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:hotels:styx:1.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:hotels:styx:1.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:hotels:styx:1.0.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:hotels:styx:1.0.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:hotels:styx:1.0.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:hotels:styx:1.0.0:beta9:*:*:*:*:*:*
- Hotels/Styxdescription
Patches
Vulnerability mechanics
References
4- github.com/HotelsDotCom/styx/security/advisories/GHSA-6v7p-v754-j89vnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-6v7p-v754-j89vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-6858ghsaADVISORY
- twitter.com/JLLeitschuhnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.