Medium severityNVD Advisory· Published Jul 9, 2026· Updated Jul 10, 2026
CVE-2026-50188
CVE-2026-50188
Description
Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), and Remote::post(), to send outgoing HTTP requests with untrusted data in the headers option could allow newline characters in a header value to inject a separate unintended request header to the remote service. This issue is fixed in versions 4.9.4 and 5.4.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getkirby/cmsPackagist | < 4.9.4 | 4.9.4 |
getkirby/cmsPackagist | >= 5.0.0-alpha.1, < 5.4.4 | 5.4.4 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-4v4h-m2qq-ppgwghsaADVISORY
- github.com/getkirby/kirby/releases/tag/4.9.4nvdWEB
- github.com/getkirby/kirby/releases/tag/5.4.4nvdWEB
- github.com/getkirby/kirby/security/advisories/GHSA-4v4h-m2qq-ppgwnvdWEB
- github.com/getkirby/kirby/commit/aa33414e1669e866cdd6f4decfae2a669e8bb828nvd
- github.com/getkirby/kirby/commit/fad9cbd22c73ed0fbd3aaf62310a8dcacfc007cdnvd
News mentions
1- Kirby CMS: Seven Bugs Patched in One Advisory, Including Critical Auth BypassVypr Intelligence · Jun 18, 2026