VYPR

Oltu

by Apache

CVEs (1)

  • CVE-2026-50630Jun 12, 2026
    risk 0.00cvss epss

    A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm…