{"id":"CVE-2020-6858","details":"Hotels Styx through 1.0.0.beta8 allows HTTP response splitting due to CRLF Injection. This is exploitable if untrusted user input can appear in a response header.","aliases":["GHSA-6v7p-v754-j89v"],"modified":"2026-08-27T08:40:20.823772Z","published":"2020-03-12T14:15:21.487Z","references":[{"type":"ADVISORY","url":"https://twitter.com/JLLeitschuh"},{"type":"EVIDENCE","url":"https://github.com/HotelsDotCom/styx/security/advisories/GHSA-6v7p-v754-j89v"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ExpediaGroup/styx","events":[{"introduced":"0"},{"last_affected":"e9407161779676a378a3d179830a2f37b8af7660"},{"introduced":"6f8b987d0928c6d58e14dbe6ce8c49a08aa76ee6"},{"last_affected":"5c6c9d4890dbc32b594e5aa52c3b63c5acffa09e"}],"database_specific":{"cpe":["cpe:2.3:a:hotels:styx:*:*:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta2:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta3:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta4:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta5:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta6:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta7:*:*:*:*:*:*","cpe:2.3:a:hotels:styx:1.0.0:beta9:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"0.7.10"},{"introduced":"1.0.0-beta1"},{"last_affected":"1.0.0-beta1"},{"introduced":"1.0.0-beta2"},{"last_affected":"1.0.0-beta2"},{"introduced":"1.0.0-beta3"},{"last_affected":"1.0.0-beta3"},{"introduced":"1.0.0-beta4"},{"last_affected":"1.0.0-beta4"},{"introduced":"1.0.0-beta5"},{"last_affected":"1.0.0-beta5"},{"introduced":"1.0.0-beta6"},{"last_affected":"1.0.0-beta6"},{"introduced":"1.0.0-beta7"},{"last_affected":"1.0.0-beta7"},{"introduced":"1.0.0-beta9"},{"last_affected":"1.0.0-beta9"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["1.0.0-beta1","1.0.0-beta2","1.0.0-beta3","1.0.0-beta4","1.0.0-beta5","1.0.0-beta6","1.0.0-beta7","1.0.0-beta9","styx-1.0.0.beta9","styx-0.7.10","styx-0.7.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-6858.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}