Loading
CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.
Cite this page
CVE-2016-1133. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2016-1133
Use Dena vendor hub and H2o product page to widen CVE-2016-1133 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2018-0608 and CVE-2023-30847 for nearby disclosures in the same product family.